Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2023-48831

Disclosure Date: December 07, 2023 (last updated February 25, 2025)
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
Attacker Value
Unknown

CVE-2023-48825

Disclosure Date: December 07, 2023 (last updated February 25, 2025)
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48208

Disclosure Date: December 07, 2023 (last updated February 25, 2025)
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
Attacker Value
Unknown

CVE-2023-48207

Disclosure Date: December 07, 2023 (last updated February 25, 2025)
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
Attacker Value
Unknown

CVE-2023-48744

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Availability Calendar: from n/a through 1.2.6.
Attacker Value
Unknown

CVE-2023-36133

Disclosure Date: August 04, 2023 (last updated February 25, 2025)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
Attacker Value
Unknown

CVE-2023-36132

Disclosure Date: August 04, 2023 (last updated February 25, 2025)
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
Attacker Value
Unknown

CVE-2023-36131

Disclosure Date: August 04, 2023 (last updated February 25, 2025)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
Attacker Value
Unknown

CVE-2023-4110

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.