Stored XSS Vulnerability in Booking Calendar Contact Form by Codepeople
CVE-2025-48231
6.5MEDIUM
What is CVE-2025-48231?
The Booking Calendar Contact Form by Codepeople suffers from a vulnerability that allows for stored cross-site scripting (XSS) attacks. This flaw arises from improper neutralization of input during web page generation, enabling attackers to inject malicious scripts that can execute in the context of a user's session. Consequently, unauthorized actions may be performed on behalf of unsuspecting users, leading to potential data breaches and compromised site integrity. Users of Booking Calendar Contact Form versions from n/a to 1.2.58 should implement immediate mitigation measures to secure their applications.
Affected Version(s)
Booking Calendar Contact Form <= 1.2.58