Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Advanced Booking Calendar MEDIUM 6.5
CVE-2022-45824

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.

Fix: after 1.7.1
Fix from $1,600 2022-12-05
Advanced Booking Calendar CRITICAL 9.8
CVE-2022-45822

Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.

Fix: after 1.7.1
Fix from $2,300 2022-12-05
Advanced Booking Calendar HIGH 7.2
CVE-2022-1006

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow h…

Fix: 1.7.1+
Fix from $1,950 2022-04-11
Advanced Booking Calendar MEDIUM 6.1
CVE-2022-1007

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin pag…

Fix: 1.7.1+
Fix from $1,600 2022-04-11
Advanced Booking Calendar CRITICAL 9.8
CVE-2022-0694

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement vi…

Fix: 1.7.0+
Fix from $2,300 2022-03-21
Advanced Booking Calendar MEDIUM 5.4
CVE-2021-24232

The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to …

Fix: 1.6.8+
Fix from $1,600 2021-04-22
Advanced Booking Calendar MEDIUM 5.4
CVE-2021-24225

The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputi…

Fix: 1.6.7+
Fix from $1,600 2021-04-12