Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-1274

Disclosure Date: April 02, 2024 (last updated April 02, 2024)
The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)
0
Attacker Value
Unknown

CVE-2024-25916

Disclosure Date: March 15, 2024 (last updated April 01, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23.
0
Attacker Value
Unknown

CVE-2023-6360

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
Attacker Value
Unknown

CVE-2023-23813

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
Attacker Value
Unknown

CVE-2022-47427

Disclosure Date: March 15, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.
Attacker Value
Unknown

CVE-2021-24927

Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2019-15713

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
The my-calendar plugin before 3.1.10 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2012-6527

Disclosure Date: January 31, 2013 (last updated December 27, 2023)
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown

CVE-2002-1626

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL.
0