THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-996f-334j-67g7 (low) — Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS

[GHSA] GHSA-996f-334j-67g7 (low) — Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS

medgithub_advisoriesPublished 2026-07-29

GHSA-996f-334j-67g7 Severity: low CVE: CVE-2026-52838

Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS

## Summary

Easy!Appointments allows administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` setting via a rich-text editor and later passed directly

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-996f-334j-67g7