Lucene search

K

Calendar Security Vulnerabilities

cve
cve

CVE-2023-4423

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.37.1 due to insufficient input sanitization and output escaping. This makes it possible...

4.8CVSS

4.8AI Score

0.0005EPSS

2023-09-27 03:19 PM
11
cve
cve

CVE-2023-40560

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2...

5.9CVSS

5.2AI Score

0.0004EPSS

2023-09-06 09:15 AM
15
cve
cve

CVE-2023-39992

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2...

7.1CVSS

6.1AI Score

0.0005EPSS

2023-09-04 11:15 AM
67
cve
cve

CVE-2023-40765

User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid...

9.8CVSS

9.2AI Score

0.001EPSS

2023-08-28 01:15 PM
18
cve
cve

CVE-2023-32511

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8...

7.1CVSS

6AI Score

0.0005EPSS

2023-08-24 12:15 PM
13
cve
cve

CVE-2023-32236

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8...

7.1CVSS

6AI Score

0.0005EPSS

2023-08-23 02:15 PM
20
cve
cve

CVE-2023-39939

SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in...

9.1CVSS

9.4AI Score

0.001EPSS

2023-08-21 09:15 AM
25
cve
cve

CVE-2023-39543

Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the...

6.1CVSS

6.3AI Score

0.001EPSS

2023-08-21 09:15 AM
24
cve
cve

CVE-2023-32122

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3...

6.1CVSS

6AI Score

0.0005EPSS

2023-08-18 04:15 PM
9
cve
cve

CVE-2023-36132

PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access...

9.8CVSS

9.5AI Score

0.001EPSS

2023-08-04 12:15 AM
17
cve
cve

CVE-2023-36133

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password...

9.8CVSS

9.4AI Score

0.001EPSS

2023-08-04 12:15 AM
17
cve
cve

CVE-2023-36131

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password...

9.8CVSS

9.6AI Score

0.001EPSS

2023-08-04 12:15 AM
15
cve
cve

CVE-2023-4117

A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely....

6.1CVSS

6AI Score

0.001EPSS

2023-08-03 08:15 AM
29
cve
cve

CVE-2023-4110

A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched...

6.1CVSS

6.2AI Score

0.003EPSS

2023-08-03 03:15 AM
26
cve
cve

CVE-2023-33562

User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid...

9.8CVSS

9.3AI Score

0.001EPSS

2023-08-01 11:15 PM
18
cve
cve

CVE-2023-33564

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar...

6.1CVSS

6AI Score

0.0005EPSS

2023-08-01 11:15 PM
18
cve
cve

CVE-2023-33561

Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure...

9.8CVSS

9.5AI Score

0.001EPSS

2023-08-01 11:15 PM
22
cve
cve

CVE-2023-33563

In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over...

8.8CVSS

8.7AI Score

0.001EPSS

2023-08-01 11:15 PM
15
cve
cve

CVE-2023-33560

There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar...

6.1CVSS

6AI Score

0.0005EPSS

2023-08-01 11:15 PM
17
cve
cve

CVE-2023-37970

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Matthew Fries MF Gig Calendar plugin <= 1.2...

6.5CVSS

5.4AI Score

0.0005EPSS

2023-07-27 03:15 PM
17
cve
cve

CVE-2023-3970

A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site...

5.4CVSS

5.4AI Score

0.001EPSS

2023-07-27 12:15 PM
28
cve
cve

CVE-2023-3969

A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to...

5.4CVSS

5.3AI Score

0.001EPSS

2023-07-27 12:15 PM
37
cve
cve

CVE-2023-3787

A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be...

5.4CVSS

5.2AI Score

0.001EPSS

2023-07-20 03:15 PM
20
cve
cve

CVE-2023-36384

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40...

7.1CVSS

6AI Score

0.001EPSS

2023-07-18 03:15 PM
19
cve
cve

CVE-2023-3558

A vulnerability classified as problematic has been found in GZ Scripts Event Booking Calendar 1.8. Affected is an unknown function of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the...

5.4CVSS

5.3AI Score

0.0004EPSS

2023-07-10 04:15 PM
15
cve
cve

CVE-2023-3544

A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack.....

6.1CVSS

6.1AI Score

0.001EPSS

2023-07-07 05:15 PM
13
cve
cve

CVE-2023-3543

A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to....

6.1CVSS

6.2AI Score

0.001EPSS

2023-07-07 05:15 PM
8
cve
cve

CVE-2023-30678

Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary...

5.5CVSS

5.5AI Score

0.0004EPSS

2023-07-06 03:15 AM
9
cve
cve

CVE-2023-2834

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as...

9.8CVSS

9.5AI Score

0.002EPSS

2023-06-30 02:15 AM
15
cve
cve

CVE-2022-4115

The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged...

5.4CVSS

5.2AI Score

0.001EPSS

2023-06-27 02:15 PM
10
cve
cve

CVE-2023-29427

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia plugin <= 1.0.75...

7.1CVSS

6AI Score

0.0005EPSS

2023-06-26 09:15 AM
22
cve
cve

CVE-2023-2414

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated.....

5.4CVSS

4.6AI Score

0.001EPSS

2023-06-09 06:16 AM
13
cve
cve

CVE-2022-4950

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a...

8.8CVSS

8.8AI Score

0.004EPSS

2023-06-07 02:15 AM
15
cve
cve

CVE-2023-2407

The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function....

6.5CVSS

6.4AI Score

0.001EPSS

2023-06-03 05:15 AM
21
cve
cve

CVE-2023-2415

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated...

5.4CVSS

5.3AI Score

0.001EPSS

2023-06-03 05:15 AM
18
cve
cve

CVE-2023-2416

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for unauthenticated to logout a vctia....

6.5CVSS

6.3AI Score

0.001EPSS

2023-06-03 05:15 AM
16
cve
cve

CVE-2023-2298

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. This makes it possible for...

7.2CVSS

5.9AI Score

0.001EPSS

2023-06-03 05:15 AM
15
cve
cve

CVE-2023-2299

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.2.10 due to a missing capability check on the processAction...

5.3CVSS

5.4AI Score

0.001EPSS

2023-06-03 05:15 AM
20
cve
cve

CVE-2023-2406

The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient....

6.4CVSS

5.3AI Score

0.004EPSS

2023-06-03 05:15 AM
22
cve
cve

CVE-2023-33183

Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or...

4.3CVSS

4.7AI Score

0.001EPSS

2023-05-30 06:16 AM
33
cve
cve

CVE-2022-46816

Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4...

8.8CVSS

8.8AI Score

0.001EPSS

2023-05-24 04:15 PM
18
cve
cve

CVE-2023-23813

Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3...

8.8CVSS

8.7AI Score

0.001EPSS

2023-05-22 09:15 AM
21
cve
cve

CVE-2023-27918

Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious...

6.1CVSS

6.2AI Score

0.002EPSS

2023-05-10 06:15 AM
19
cve
cve

CVE-2023-28169

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0...

5.9CVSS

4.8AI Score

0.0005EPSS

2023-05-08 01:15 PM
13
cve
cve

CVE-2015-10099

A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to...

9.8CVSS

9.8AI Score

0.002EPSS

2023-04-10 12:15 PM
22
cve
cve

CVE-2013-10023

A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The...

9.8CVSS

9.8AI Score

0.001EPSS

2023-04-08 09:15 AM
15
cve
cve

CVE-2023-24402

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18...

5.9CVSS

4.9AI Score

0.0005EPSS

2023-04-07 09:15 AM
17
cve
cve

CVE-2022-47438

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3...

5.9CVSS

5.2AI Score

0.001EPSS

2023-03-29 01:15 PM
21
cve
cve

CVE-2023-1400

The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...

4.8CVSS

4.8AI Score

0.001EPSS

2023-03-27 04:15 PM
27
cve
cve

CVE-2022-45814

Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3...

5.4CVSS

5.2AI Score

0.001EPSS

2023-03-17 02:15 PM
20
Total number of security vulnerabilities417