Unknown · Librebooking · CVE-2026-61343
**Name of the Vulnerable Software and Affected Versions**
LibreBooking versions prior to 5.1.0
**Description**
The email template editor save action allows a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. This occurs because the submitted template name is passed directly into the destination file path.
**Recommendations**
Update to version 5.1.0.