📦 Bookgy

by Bookgy

🔍 What is Bookgy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-40617

CRITICAL CVSS 9.8 Apr 29, 2025

A critical SQL injection vulnerability in Bookgy allows attackers to manipulate database operations through unvalidated HTTP parameters. Attackers can execute arbitrary SQL commands to retrieve, modif...

CVE-2025-40619

HIGH CVSS 7.5 Apr 29, 2025

Bookgy contains an authorization bypass vulnerability (CWE-863) that allows unauthenticated attackers to access private areas or functionality intended for other user roles. This affects all Bookgy in...

CVE-2025-40616

MEDIUM CVSS 6.1 Apr 29, 2025

This reflected XSS vulnerability in Bookgy allows attackers to inject malicious JavaScript via the IDRESERVA parameter in /bkg_imprimir_comprobante.php. When victims click a specially crafted link, th...