Known Vulnerabilities for Event Calendar by Total-soft
Listed below are 2 of the newest known vulnerabilities associated with "Event Calendar" by "Total-soft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87012 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_w... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-81814 json | Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case title... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-78159 json | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.1... | Not Provided | 2026-09-12 | 2026-09-12 |
| CVE-2026-78006 json | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.1... | Not Provided | 2026-09-12 | 2026-09-12 |
| CVE-2026-77353 json | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated us... | Not Provided | 2026-08-31 | 2026-09-03 |
| CVE-2026-77187 json | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' a... | Not Provided | 2026-09-09 | 2026-09-11 |
| CVE-2026-77186 json | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback'... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-68527 json | Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concre... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-68526 json | Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/con... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-63643 json | MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/ca... | Not Provided | 2026-08-18 | 2026-08-19 |