CVE-2023-48839: Phpjabbers Appointment Scheduler
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Affected products
- Phpjabbers Appointment Scheduler: version 3.0 only
Published 2023-12-07. Last modified 2026-06-17.