Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Booking Calendar MEDIUM 6.1
CVE-2023-36384

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.

Fix: after 1.2.40
Fix from $1,600 2023-07-18
Booking Calendar HIGH 8.8
CVE-2022-1463

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and includ…

Fix: after 9.1
Fix from $1,950 2022-05-10
Booking Calendar MEDIUM 6.1
CVE-2021-25040

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page…

Fix: 8.9.2+
Fix from $1,600 2022-01-03
Booking Calendar HIGH 8.8
CVE-2018-20556EPSS 19%

SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_…

No fix yet
Fix from $1,950 2019-03-21
Booking Calendar HIGH 8.8
CVE-2018-5673

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.

No fix yet
Fix from $1,950 2018-01-13
Booking Calendar MEDIUM 6.1
CVE-2017-2151

Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns…

Fix: after 7.1
Fix from $1,600 2017-04-28
Booking Calendar MEDIUM 5.3
CVE-2017-2150

Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted c…

Fix: after 7.0
Fix from $1,600 2017-04-28