Show filters
116 Total Results
Displaying 91-100 of 116
Sort by:
Attacker Value
Unknown

CVE-2022-1006

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks
Attacker Value
Unknown

CVE-2022-0694

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection
Attacker Value
Unknown

CVE-2021-25040

Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-24726

Disclosure Date: September 13, 2021 (last updated February 23, 2025)
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
Attacker Value
Unknown

CVE-2021-24232

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-24225

Disclosure Date: April 12, 2021 (last updated February 22, 2025)
The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue
Attacker Value
Unknown

CVE-2020-9372

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
Attacker Value
Unknown

CVE-2016-10916

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
0
Attacker Value
Unknown

CVE-2016-10909

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
0
Attacker Value
Unknown

CVE-2016-10908

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
0