Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2025-67559

Missing Authorization vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Exploiting…

Fix: 4.6.0+
Fix from $1,600 2025-12-09
Online Booking \& Scheduling Calendar HIGH 8.8
CVE-2025-67472

Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allow…

Fix: 4.6.0+
Fix from $1,950 2025-12-09
Online Booking \& Scheduling Calendar HIGH 7.2
CVE-2025-54677

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-…

Fix: 4.5.5+
Fix from $1,950 2025-08-20
Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2025-54676

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for …

Fix: 4.5.5+
Fix from $1,600 2025-08-14
Crm And Lead Management By Vcita MEDIUM 5.4
CVE-2024-13702

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler' and '…

Fix: 2.7.5+
Fix from $1,600 2025-03-26
Online Payments Get Paid With Paypal\, Square \& Stripe MEDIUM 5.4
CVE-2024-11895

The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc…

Fix: 3.30.0+
Fix from $1,600 2025-02-18
Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2024-54356

Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allow…

Fix: 4.5.2+
Fix from $1,600 2024-12-16
Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2024-9872

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a miss…

Fix: 4.5.2+
Fix from $1,600 2024-12-06
Online Booking \& Scheduling Calendar MEDIUM 6.1
CVE-2024-47638

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for …

Fix: 4.5+
Fix from $1,600 2024-10-05
Online Booking \& Scheduling Calendar MEDIUM 6.1
CVE-2024-37262

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Ca…

Fix: 4.4.3+
Fix from $1,600 2024-07-22
Online Booking \& Scheduling Calendar MEDIUM 6.5
CVE-2024-37499

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & Scheduling Calendar for WordPr…

Fix: 4.4.3+
Fix from $1,600 2024-07-09
Online Booking \& Scheduling Calendar MEDIUM 6.1
CVE-2024-5791

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' par…

Fix: 4.4.3+
Fix from $1,600 2024-06-22
Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2024-35761

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calend…

Fix: 4.4.1+
Fix from $1,600 2024-06-21
Online Booking \& Scheduling Calendar MEDIUM 6.1
CVE-2024-5859

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ para…

Fix: 4.2.3+
Fix from $1,600 2024-06-21
Online Booking \& Scheduling Calendar MEDIUM 6.1
CVE-2023-39992

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 v…

Fix: 4.3.3+
Fix from $1,600 2023-09-04
Crm And Lead Management By Vcita MEDIUM 6.5
CVE-2023-2405

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This i…

Fix: after 2.6.2
Fix from $1,600 2023-06-03
Event Registration Calendar By Vcita MEDIUM 6.5
CVE-2023-2407

The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plu…

Fix: after 3.9.1
Fix from $1,600 2023-06-03
Online Booking \& Scheduling Calendar MEDIUM 6.5
CVE-2023-2416

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing non…

Fix: after 4.2.10
Fix from $1,600 2023-06-03
Online Booking \& Scheduling Calendar MEDIUM 6.1
CVE-2023-2298

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_i…

Fix: after 4.2.10
Fix from $1,600 2023-06-03
Contact Form Builder By Vcita MEDIUM 6.1
CVE-2023-2301

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.3. This is …

Fix: after 4.9.1
Fix from $1,600 2023-06-03
Contact Form And Calls To Action By Vcita MEDIUM 6.1
CVE-2023-2303

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10…

Fix: after 2.6.4
Fix from $1,600 2023-06-03
Contact Form Builder By Vcita MEDIUM 5.4
CVE-2023-2300

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and …

Fix: after 4.9.1
Fix from $1,600 2023-06-03
Contact Form And Calls To Action By Vcita MEDIUM 5.4
CVE-2023-2302

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions…

Fix: after 2.6.4
Fix from $1,600 2023-06-03
Crm And Lead Management By Vcita MEDIUM 5.4
CVE-2023-2404

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, a…

Fix: after 2.6.2
Fix from $1,600 2023-06-03
Event Registration Calendar By Vcita MEDIUM 5.4
CVE-2023-2406

The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plug…

Fix: after 3.9.1
Fix from $1,600 2023-06-03
Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2023-2415

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a miss…

Fix: after 4.2.10
Fix from $1,600 2023-06-03
Online Booking \& Scheduling Calendar MEDIUM 5.3
CVE-2023-2299

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-jso…

Fix: after 4.2.10
Fix from $1,600 2023-06-03