Show filters
116 Total Results
Displaying 91-100 of 116
Sort by:
Attacker Value
Unknown
CVE-2022-1006
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks
0
Attacker Value
Unknown
CVE-2022-0694
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection
0
Attacker Value
Unknown
CVE-2021-25040
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-24726
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
0
Attacker Value
Unknown
CVE-2021-24232
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-24225
Disclosure Date: April 12, 2021 (last updated February 22, 2025)
The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue
0
Attacker Value
Unknown
CVE-2020-9372
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
0
Attacker Value
Unknown
CVE-2016-10916
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
0
Attacker Value
Unknown
CVE-2016-10909
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
0
Attacker Value
Unknown
CVE-2016-10908
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
0