Unknown · Truebooker · CVE-2026-18778
**Name of the Vulnerable Software and Affected Versions**
TrueBooker versions prior to 1.2.7
**Description**
Lack of proper authorization checks in several AJAX actions allows unauthenticated users to retrieve personally identifiable information (PII) of customers who booked appointments. The exposed data includes names, email addresses, phone numbers, and postal addresses.
**Recommendations**
Update TrueBooker to version 1.2.7 or later.