Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-45824 Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. Advanced Booking Calendar after 1.7.1 Fix from $1,6002022-12-05 CRITICAL 9.8 CVE-2022-45822 Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. Advanced Booking Calendar after 1.7.1 Fix from $2,3002022-12-05 HIGH 7.2 CVE-2022-1006 The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow h… Advanced Booking Calendar 1.7.1+ Fix from $1,9502022-04-11 MEDIUM 6.1 CVE-2022-1007 The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin pag… Advanced Booking Calendar 1.7.1+ Fix from $1,6002022-04-11 CRITICAL 9.8 CVE-2022-0694 The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement vi… Advanced Booking Calendar 1.7.0+ Fix from $2,3002022-03-21 MEDIUM 5.4 CVE-2021-24232 The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to … Advanced Booking Calendar 1.6.8+ Fix from $1,6002021-04-22 MEDIUM 5.4 CVE-2021-24225 The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputi… Advanced Booking Calendar 1.6.7+ Fix from $1,6002021-04-12