CVE-2023-51296: Phpjabbers Event Booking Calendar
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code
Affected products
- Phpjabbers Event Booking Calendar: version 4.0 only
Published 2025-02-19. Last modified 2026-06-17.