CVE-2023-23012: Classroombookings

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php.

Affected products

Published 2023-01-20. Last modified 2026-06-17.