{"api_version":"v1","generated_at":"2026-10-07T20:35:00+00:00","product":{"cve_count":6,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-bookly-bookly-e9d21f1c97c8","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/bookly","name":"Bookly","next_cursor":null,"observations":[{"affected":"Bookly: n/a \u2264 28.2","affected_versions_present":true,"cve_id":"CVE-2026-96348","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96348","fixed":"Update the WordPress Bookly plugin to the latest available version (at least 28.3).","last_modified":"2026-09-30T13:27:06.638Z","patch_url":"https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-28-2-broken-access-control-vulnerability?_s_id=cve","primary_source":"","published":"2026-09-30T12:27:24.147Z"},{"affected":"Bookly: n/a \u2264 28.2","affected_versions_present":true,"cve_id":"CVE-2026-96347","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96347","fixed":"Update the WordPress Bookly plugin to the latest available version (at least 28.3).","last_modified":"2026-09-30T13:27:06.513Z","patch_url":"https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-28-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve","primary_source":"","published":"2026-09-30T12:27:23.350Z"},{"affected":"n/a \u2264 27.7","affected_versions_present":true,"cve_id":"CVE-2026-61949","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61949","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-23T15:59:35.105Z","patch_url":"","primary_source":"","published":"2026-07-23T11:18:28.614Z"},{"affected":"n/a \u2264 27.7","affected_versions_present":true,"cve_id":"CVE-2026-61944","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61944","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-23T13:31:29.688Z","patch_url":"","primary_source":"","published":"2026-07-23T11:18:26.009Z"},{"affected":"n/a \u2264 27.4","affected_versions_present":true,"cve_id":"CVE-2026-42667","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42667","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-16T01:24:43.572Z","patch_url":"","primary_source":"","published":"2026-06-15T20:18:46.425Z"},{"affected":"n/a \u2264 <= 26.7","affected_versions_present":true,"cve_id":"CVE-2026-32540","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32540","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T09:52:01.368Z","patch_url":"","primary_source":"","published":"2026-03-25T16:15:11.278Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Bookly"}}
