CVE-2026-97248

CRITICALCVSS 9.8

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.

Published 2026-09-30 · last modified 2026-09-30

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.