Show filters
107 Total Results
Displaying 31-40 of 107
Sort by:
Attacker Value
Unknown
CVE-2024-3022
Disclosure Date: April 04, 2024 (last updated April 10, 2024)
The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_upload' function in all versions up to, and including 1.0.87. This allows an authenticated attacker with administrator-level capabilities or higher to upload arbitrary files on the affected site's server, enabling remote code execution.
0
Attacker Value
Unknown
CVE-2024-30561
Disclosure Date: March 31, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scientech It Solution Appointment Calendar allows Reflected XSS.This issue affects Appointment Calendar: from n/a through 2.9.6.
0
Attacker Value
Unknown
CVE-2024-0856
Disclosure Date: March 20, 2024 (last updated April 02, 2024)
The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.
0
Attacker Value
Unknown
CVE-2023-49173
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10to8 Sign In Scheduling Online Appointment Booking System allows Stored XSS.This issue affects Sign In Scheduling Online Appointment Booking System: from n/a through 1.0.9.
0
Attacker Value
Unknown
CVE-2023-48841
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
0
Attacker Value
Unknown
CVE-2023-48840
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
0
Attacker Value
Unknown
CVE-2023-48839
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
0
Attacker Value
Unknown
CVE-2023-48838
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
0
Attacker Value
Unknown
CVE-2023-46198
Disclosure Date: October 25, 2023 (last updated November 02, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Scientech It Solution Appointment Calendar plugin <= 2.9.6 versions.
0
Attacker Value
Unknown
CVE-2023-36127
Disclosure Date: October 10, 2023 (last updated October 14, 2023)
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
0