Show filters
116 Total Results
Displaying 41-50 of 116
Sort by:
Attacker Value
Unknown

CVE-2024-1484

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the date parameters in all versions up to, and including, 1.0.98 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2024-1207

Disclosure Date: February 08, 2024 (last updated February 15, 2024)
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2023-51520

Disclosure Date: February 01, 2024 (last updated February 07, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.
Attacker Value
Unknown

CVE-2023-48833

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
Attacker Value
Unknown

CVE-2023-48831

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
Attacker Value
Unknown

CVE-2023-48828

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Attacker Value
Unknown

CVE-2023-48827

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Attacker Value
Unknown

CVE-2023-48826

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
Attacker Value
Unknown

CVE-2023-48825

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48208

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.