Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
booking calendar vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2023-2415
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for...
Vcita Online Booking \\& Scheduling Calendar For Wordpress By Vcita
6.5
CVSSv3
CVE-2023-2416
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for unauthentic...
Vcita Online Booking \\& Scheduling Calendar For Wordpress By Vcita
6.1
CVSSv3
CVE-2023-39992
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.
Vcita Online Booking \\& Scheduling Calendar For Wordpress By Vcita
8.8
CVSSv3
CVE-2023-51354
Cross-Site Request Forgery (CSRF) vulnerability in WebbaPlugins Appointment & Event Booking Calendar Plugin – Webba Booking.This issue affects Appointment & Event Booking Calendar Plugin – Webba Booking: from n/a up to and including 4.5.33.
Webba-booking Webba Booking
6.1
CVSSv3
CVE-2021-20840
Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions before 1.5.11 allows a remote malicious user to inject an arbitrary script via unspecified vectors.
Saasproject Booking Package
4.8
CVSSv3
CVE-2023-24402
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions.
Wpbookingsystem Wp Booking System
7.5
CVSSv3
CVE-2022-0709
The Booking Package WordPress plugin prior to 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnera...
Saasproject Booking Package
4.8
CVSSv3
CVE-2021-24673
The Appointment Hour Booking WordPress plugin prior to 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Dwbooster Appointment Hour Booking
4.8
CVSSv3
CVE-2022-1710
The Appointment Hour Booking WordPress plugin prior to 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Dwbooster Appointment Hour Booking
9.8
CVSSv3
CVE-2022-24838
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out ...
Nextcloud Calendar
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »