Vulnerabilities > Booking Calendar Project > Booking Calendar > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-18 | CVE-2023-36384 | Unspecified vulnerability in Booking Calendar Project Booking Calendar Unauth. | 6.1 |
2022-01-03 | CVE-2021-25040 | Cross-site Scripting vulnerability in Booking Calendar Project Booking Calendar The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | 6.1 |
2018-01-13 | CVE-2018-5672 | Cross-site Scripting vulnerability in Booking Calendar Project Booking Calendar 2.1.7 An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. | 4.8 |
2018-01-13 | CVE-2018-5671 | Cross-site Scripting vulnerability in Booking Calendar Project Booking Calendar 2.1.7 An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. | 4.8 |
2018-01-13 | CVE-2018-5670 | Cross-site Scripting vulnerability in Booking Calendar Project Booking Calendar 2.1.7 An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. | 4.8 |
2017-04-28 | CVE-2017-2151 | Cross-site Scripting vulnerability in Booking Calendar Project Booking Calendar Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |
2017-04-28 | CVE-2017-2150 | Path Traversal vulnerability in Booking Calendar Project Booking Calendar Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. | 5.3 |