Unauthenticated SQL Injection in Simply Schedule Appointments by SimplySchedule
CVE-2026-65508
9.3CRITICAL
What is CVE-2026-65508?
An unauthenticated SQL Injection vulnerability has been identified in Simply Schedule Appointments versions up to 1.6.12.10. This flaw allows attackers to exploit the application's database queries, potentially leading to unauthorized access and manipulation of sensitive information. Users are advised to update to the latest version to mitigate this security risk.
Affected Version(s)
Simply Schedule Appointments <= 1.6.12.10