Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16.
CVE ID: CVE-2025-22719
CVSS Base Severity: HIGH
CVSS Base Score: 7.1
Vendor: E4J s.r.l.
Product: VikAppointments Services Booking Calendar
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.7% (scored less or equal to compared to others)
EPSS Date: 2025-02-19 (when was this score calculated)