Show filters
116 Total Results
Displaying 51-60 of 116
Sort by:
Attacker Value
Unknown

CVE-2023-48207

Disclosure Date: December 07, 2023 (last updated December 12, 2023)
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
Attacker Value
Unknown

CVE-2022-47428

Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.
Attacker Value
Unknown

CVE-2023-4620

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
Attacker Value
Unknown

CVE-2023-39992

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.
Attacker Value
Unknown

CVE-2023-40765

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Attacker Value
Unknown

CVE-2023-32511

Disclosure Date: August 24, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions.
Attacker Value
Unknown

CVE-2023-32236

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions.
Attacker Value
Unknown

CVE-2023-36133

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
Attacker Value
Unknown

CVE-2023-36132

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
Attacker Value
Unknown

CVE-2023-36131

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.