Show filters
461 Total Results
Displaying 51-60 of 461
Sort by:
Attacker Value
Unknown
CVE-2023-25037
Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in CodePeople Booking Calendar Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar Contact Form: from n/a through 1.2.34.
0
Attacker Value
Unknown
CVE-2023-24407
Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
0
Attacker Value
Unknown
CVE-2023-23895
Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82.
0
Attacker Value
Unknown
CVE-2024-53815
Disclosure Date: December 06, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Blind SQL Injection.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.1.
0
Attacker Value
Unknown
CVE-2024-9872
Disclosure Date: December 06, 2024 (last updated February 27, 2025)
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_user_data_callback() function in all versions up to, and including, 4.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject malicious web scripts and update settings.
0
Attacker Value
Unknown
CVE-2024-54221
Disclosure Date: December 05, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roninwp FAT Services Booking.This issue affects FAT Services Booking: from n/a through 5.6.
0
Attacker Value
Unknown
CVE-2024-10893
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2024-53762
Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Faster Themes FastBook – Responsive Appointment Booking and Scheduling System allows Stored XSS.This issue affects FastBook – Responsive Appointment Booking and Scheduling System: from n/a through 1.1.
0
Attacker Value
Unknown
CVE-2024-53753
Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in CultBooking CultBooking Hotel Booking Engine allows Stored XSS.This issue affects CultBooking Hotel Booking Engine: from n/a through 2.1.
0
Attacker Value
Unknown
CVE-2024-9504
Disclosure Date: November 26, 2024 (last updated February 27, 2025)
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0