CVE-2025-24732: Reputeinfosystems Bookingpress
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems BookingPress bookingpress-appointment-booking allows DOM-Based XSS.This issue affects BookingPress: from n/a through <= 1.1.25.
Affected products
- Reputeinfosystems Bookingpress: before 1.1.26 (fixed in 1.1.26)
Published 2025-01-24. Last modified 2026-06-17.