CVE-2025-22719
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-22719 is a Cross-site Scripting (XSS) vulnerability affecting the VikAppointments Services Booking Calendar from E4J s.r.l. The issue stems from improper neutralization of user inputs during web page generation. An attacker can inject malicious scripts into the calendar, which are then stored and executed on vulnerable pages. This affects versions of the VikAppointments Services Booking Calendar from n/a up to and including 1.2.16. Successful exploitation of this vulnerability can lead to unauthorized access to user data or even complete website takeover. Users are advised to update to the latest, secure version of the VikAppointments Services Booking Calendar to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.