Known Vulnerabilities for products from Booking Calendar Project
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Booking Calendar Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-36384 json | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 vers... | 6.1 - MEDIUM | 2023-07-18 | 2023-07-27 |
| CVE-2022-1463 json | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in ve... | 8.8 - HIGH | 2022-05-10 | 2022-05-17 |
| CVE-2021-25040 json | The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting ... | 6.1 - MEDIUM | 2022-01-03 | 2022-01-08 |
| CVE-2018-20556 json | SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL c... | 8.8 - HIGH | 2019-03-21 | 2019-05-09 |
| CVE-2018-5673 json | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. | 8.8 - HIGH | 2018-01-13 | 2019-03-05 |
| CVE-2018-5672 json | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5... | 4.8 - MEDIUM | 2018-01-13 | 2019-03-05 |
| CVE-2018-5671 json | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field... | 4.8 - MEDIUM | 2018-01-13 | 2019-03-05 |
| CVE-2018-5670 json | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_condit... | 4.8 - MEDIUM | 2018-01-13 | 2019-03-05 |
| CVE-2017-2151 json | Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary we... | Not Provided | 2017-04-28 | 2025-04-20 |
| CVE-2017-2150 json | Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files... | Not Provided | 2017-04-28 | 2025-04-20 |
Known software with vulnerabilities from Booking Calendar Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Booking Calendar Project | Booking Calendar | 0.5 |