| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-6009 | itsourcecode Event Calendar process.php regDelete sql injection | itsourcecode | Event Calendar | Medium | 6.3 | 2024-06-15 15:31:04 | Deep Dive |
| CVE-2024-1295 | The Events Calendar (Free < 6.4.0.1, Pro < 6.4.0.1) - Contributor+ Arbitrary Events Access | Unknown | events-calendar-pro | - | - | 2024-06-14 06:00:02 | Deep Dive |
| CVE-2024-1094 | Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation | arraytics | Timetics – Appointment Booking & Scheduling | High | 7.3 | 2024-06-14 04:36:55 | Deep Dive |
| CVE-2024-3492 | Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes | netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | Medium | 6.4 | 2024-06-12 11:05:09 | Deep Dive |
| CVE-2024-30528 | WordPress Spiffy Calendar plugin <= 4.9.10 - Broken Access Control vulnerability | Spiffy Plugins | Spiffy Calendar | Medium | 5.4 | 2024-06-04 19:19:50 | Deep Dive |
| CVE-2024-4180 | The Events Calendar < 6.4.0.1 - Reflected XSS | Unknown | The Events Calendar | - | - | 2024-06-04 06:00:03 | Deep Dive |
| CVE-2023-28492 | WordPress Calendar Event Multi View plugin <= 1.4.10 - Missing Authorization Leading To Feedback Submission vulnerability | CodePeople | CP Multi View Event Calendar | Medium | 4.3 | 2024-06-03 22:09:38 | Deep Dive |
| CVE-2023-24373 | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability | WpDevArt | Booking calendar, Appointment Booking System | Low | 3.7 | 2024-06-03 21:35:58 | Deep Dive |
| CVE-2024-24715 | WordPress WordPress BookIt Plugin plugin <= 2.4.0 - Price Bypass Vulnerability vulnerability | The Events Calendar | BookIt | Medium | 6.5 | 2024-05-17 08:48:05 | Deep Dive |
| CVE-2023-46784 | WordPress ICS Calendar plugin <= 10.12.0.3 - SSRF and Arbitrary File Read vulnerability | Room 34 Creative Services, LLC | ICS Calendar | High | 8.2 | 2024-05-17 08:34:46 | Deep Dive |
| CVE-2024-4288 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting | croixhaug | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | Medium | 6.4 | 2024-05-16 11:05:29 | Deep Dive |
| CVE-2024-3755 | MF Gig Calendar <= 1.2.1 - Editor+ Stored XSS | Unknown | MF Gig Calendar | - | - | 2024-05-06 06:00:02 | Deep Dive |
| CVE-2024-3756 | MF Gig Calendar <= 1.2.1 - Arbitrary Event Deletion via CSRF | Unknown | MF Gig Calendar | - | - | 2024-05-06 06:00:02 | Deep Dive |
| CVE-2024-2831 | Calendar <= 1.3.14 - Authenticated (Contributor+) SQL Injection via Shortcode | kieranoshea | Calendar | High | 8.8 | 2024-05-02 16:51:44 | Deep Dive |
| CVE-2024-33950 | WordPress Archives Calendar Widget plugin <= 1.0.15 - Cross Site Scripting (XSS) vulnerability | Aleksei Polechin (alek´) | Archives Calendar Widget | Medium | 5.9 | 2024-05-02 11:32:15 | Deep Dive |
| CVE-2024-33640 | WordPress Pretty Google Calendar plugin <= 1.7.2 - Cross Site Scripting (XSS) vulnerability | LBell | Pretty Google Calendar | Medium | 6.5 | 2024-04-29 05:02:20 | Deep Dive |
| CVE-2024-33651 | WordPress MF Gig Calendar plugin <= 1.2.1 - Cross Site Request Forgery (CSRF) vulnerability | Matthew Fries | MF Gig Calendar | Medium | 5.4 | 2024-04-26 07:09:47 | Deep Dive |
| CVE-2024-31433 | WordPress The Events Calendar plugin <= 6.3.0 - Cross Site Request Forgery (CSRF) vulnerability | StellarWP | The Events Calendar | Medium | 4.3 | 2024-04-15 09:29:42 | Deep Dive |
| CVE-2024-2341 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Subscriber+) SQL Injection | croixhaug | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | High | 8.8 | 2024-04-09 18:59:30 | Deep Dive |
| CVE-2024-2342 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.7.7 - Authenticated (Contributor+) SQL Injection via Shortcode | croixhaug | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | High | 8.8 | 2024-04-09 18:58:31 | Deep Dive |