| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-3543 | GZ Scripts Availability Booking Calendar PHP HTTP POST Request load.php cross site scripting | GZ Scripts | Availability Booking Calendar PHP | Low | 3.5 | 2023-07-07 16:31:03 | Deep Dive |
| CVE-2023-30678 | SAMSUNG Calendar 路径遍历漏洞 | Samsung Mobile | Calendar | Medium | 5.1 | 2023-07-06 02:51:51 | Deep Dive |
| CVE-2023-2834 | BookIt <= 2.3.7 - Authentication Bypass | stellarwp | Bookit — Booking & Appointment Calendar | Critical | 9.8 | 2023-06-30 01:56:18 | Deep Dive |
| CVE-2022-4115 | Editorial Calendar < 3.8.3 - Contributor+ Stored XSS | Unknown | Editorial Calendar | 中危 | - | 2023-06-27 13:17:15 | Deep Dive |
| CVE-2023-29427 | WordPress Amelia Plugin <= 1.0.75 is vulnerable to Cross Site Scripting (XSS) | TMS | Booking for Appointments and Events Calendar – Amelia | High | 7.1 | 2023-06-26 08:32:56 | Deep Dive |
| CVE-2023-2414 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Missing Authorization to Settings Update and Arbitrary File Upload | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | Medium | 5.4 | 2023-06-09 05:33:15 | Deep Dive |
| CVE-2022-4950 | Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation | narinder-singh | The Events Calendar Events Notification Bar Addon | High | 8.8 | 2023-06-07 01:51:53 | Deep Dive |
| CVE-2023-2416 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery to Account Logout | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | Medium | 5.4 | 2023-06-03 04:35:17 | Deep Dive |
| CVE-2023-2298 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site Scripting | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | High | 7.2 | 2023-06-03 04:35:16 | Deep Dive |
| CVE-2023-2415 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 - Missing Authorization to Account Logout | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | Medium | 5.4 | 2023-06-03 04:35:16 | Deep Dive |
| CVE-2023-2299 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Missing Authorization on REST-API | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | Medium | 5.3 | 2023-06-03 04:35:14 | Deep Dive |
| CVE-2023-2406 | Event Registration Calendar By vcita <= 1.3.1 & Online Payments – Get Paid with PayPal, Square & Stripe <= 3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | vcita | Event Registration Calendar By vcita | Medium | 6.4 | 2023-06-03 04:35:13 | Deep Dive |
| CVE-2023-2407 | Event Registration Calendar By vcita <= 1.3.1 & Online Payments – Get Paid with PayPal, Square & Stripe <= 3.10.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting | vcita | Event Registration Calendar By vcita | Medium | 6.1 | 2023-06-03 04:35:13 | Deep Dive |
| CVE-2022-46816 | WordPress Booking Ultra Pro Plugin <= 1.1.4 is vulnerable to Cross Site Request Forgery (CSRF) | Booking Ultra Pro | Booking Ultra Pro Appointments Booking Calendar Plugin | Medium | 4.3 | 2023-05-24 15:45:23 | Deep Dive |
| CVE-2023-23813 | WordPress My Calendar Plugin <= 3.4.3 is vulnerable to Cross Site Request Forgery (CSRF) | Joseph C Dolson | My Calendar | Medium | 5.4 | 2023-05-22 08:24:09 | Deep Dive |
| CVE-2023-27918 | WordPress plugin Appointment and Event Booking Calendar for WordPress 跨站脚本漏洞 | TMS | Appointment and Event Booking Calendar for WordPress - Amelia | 中危 | - | 2023-05-10 00:00:00 | Deep Dive |
| CVE-2023-28169 | WordPress Easy Event calendar Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) | CoreFortress | Easy Event calendar | Medium | 5.9 | 2023-05-08 12:22:33 | Deep Dive |
| CVE-2015-10099 | CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injection | - | CP Appointment Calendar Plugin | Medium | 6.3 | 2023-04-10 12:00:06 | Deep Dive |
| CVE-2013-10023 | Editorial Calendar Plugin edcal.php edcal_filter_where sql injection | - | Editorial Calendar Plugin | Medium | 6.3 | 2023-04-08 09:00:05 | Deep Dive |
| CVE-2023-24402 | WordPress WP Booking System Plugin <= 2.0.18 is vulnerable to Cross Site Scripting (XSS) | Veribo, Roland Murg | WP Booking System – Booking Calendar | Medium | 5.9 | 2023-04-07 08:48:20 | Deep Dive |