CVE-2026-52838
Summary
Easy!Appointments allows administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the disable_booking_message setting via a rich-text editor and later passed directly to the public booking_message view without escaping or sanitization:
<p><?= vars('message_text') ?></p>
An authenticated administrator can store HTML or JavaScript in this field, enable disabled-booking mode, and trigger stored XSS in every unauthenticated visitor who opens the public booking page.
Root Cause — Step by Step Code Flow
Step 1 — Rich text editor value stored without sanitization
The booking settings page collects the message value from the Trumbowyg rich-text editor and submits it as raw HTML:
// assets/js/pages/booking_settings.js line 61-92
bookingSettings.push({
name: 'disable_booking_message',
value: $disableBookingMessage.trumbowyg('html'),
});
Step 2 — Settings controller saves value verbatim
The backend settings controller persists the submitted value without any HTML sanitization:
// application/controllers/Booking_settings.php line 76-104
$this->settings_model->save($setting);
Step 3 — Public booking controller forwards stored value to view
When booking is disabled, the public booking controller loads the stored message and passes it directly to the view:
// application/controllers/Booking.php line 113-132
$disable_booking_message = setting('disable_booking_message');
html_vars([
'message_text' => $disable_booking_message,
]);
Step 4 — Public view renders value without escaping
The booking message view emits the value raw using PHP's short echo tag with no escaping:
// application/views/pages/booking_message.php line 10-12
<p><?= vars('message_text') ?></p>
No htmlspecialchars(), no sanitization, no template escaping is applied at any point in this rendering path.
Proof of Concept
Step 1 — Store malicious disabled-booking message as admin:
POST /index.php/booking_settings/save HTTP/1.1
Host: 1
⚡ Watch CVE-2026-52838
Get an email if CVE-2026-52838 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-52838)