Vulnerabilities > Booking Calendar Project > High

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2022-1463 Unspecified vulnerability in Booking Calendar Project Booking Calendar
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1.
network
low complexity
booking-calendar-project
8.8
2019-03-21 CVE-2018-20556 SQL Injection vulnerability in Booking Calendar Project Booking Calendar 8.4.3
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
network
low complexity
booking-calendar-project CWE-89
8.8
2018-01-13 CVE-2018-5673 Cross-Site Request Forgery (CSRF) vulnerability in Booking Calendar Project Booking Calendar 2.1.7
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress.
network
low complexity
booking-calendar-project CWE-352
8.8