Show filters
116 Total Results
Displaying 41-50 of 116
Sort by:
Attacker Value
Unknown
CVE-2024-1484
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-1207
Disclosure Date: February 08, 2024 (last updated February 15, 2024)
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2023-51520
Disclosure Date: February 01, 2024 (last updated February 07, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.
0
Attacker Value
Unknown
CVE-2023-48833
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
0
Attacker Value
Unknown
CVE-2023-48831
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
0
Attacker Value
Unknown
CVE-2023-48828
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
0
Attacker Value
Unknown
CVE-2023-48827
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
0
Attacker Value
Unknown
CVE-2023-48826
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
0
Attacker Value
Unknown
CVE-2023-48825
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
0
Attacker Value
Unknown
CVE-2023-48208
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
0