CVE-2023-51295: Phpjabbers Event Booking Calendar
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
Affected products
- Phpjabbers Event Booking Calendar: version 4.0 only
Published 2025-05-08. Last modified 2026-06-17.