Classroombookings is an educational scheduling application whose vulnerability profile centers on web-based input-handling weaknesses, specifically cross-site scripting and SQL injection flaws in its core booking platform. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Classroombookings over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35382HIGH SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user. | Dec 14, 2020 | 7.2 | 22 | NO | NO |
CVE-2023-23012MEDIUM Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file | Jan 20, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-9806MEDIUM A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the | Oct 10, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-9807MEDIUM A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component S | Oct 10, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Classroombookings.
Media articles that mention a CVE ID that affects a product developed by Classroombookings — matched by CVE ID, not by vendor name.