Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-56059: Travel Booking <= 2.2.5: Unsecured File Uploads
CVE-2026-56059
Summary
Travel Booking software versions 2.2.5 and earlier allow attackers to upload unauthorized files. This could lead to malicious code being executed on the server, potentially compromising the entire system. Upgrade to the latest version to fix this security issue.
Original title
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
Original description
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
nvd CVSS3.1
9.9
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 26 Jun 2026 · Updated: 23 Jul 2026 · First seen: 26 Jun 2026