Medium severity6.1NVD Advisory· Published Feb 19, 2025· Updated Jun 17, 2026
CVE-2023-51296
CVE-2023-51296
Description
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:phpjabbers:event_booking_calendar:4.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:phpjabbers:event_booking_calendar:4.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 4.0
Patches
Vulnerability mechanics
References
3- packetstorm.news/files/id/176485nvdExploitThird Party AdvisoryVDB Entry
- www.phpjabbers.com/event-booking-calendar/nvdProduct
- packetstormsecurity.com/files/176485/PHPJabbers-Event-Booking-Calendar-4.0-Cross-Site-Scripting-HTML-Injection.htmlnvd
News mentions
0No linked articles in our index yet.