CVE-2025-66918: Hashenudara Edoc-Doctor-Appointment-System

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.

Affected products

  • Hashenudara Edoc-Doctor-Appointment-System: version 1.0.1 only

Published 2025-12-11. Last modified 2026-06-17.