| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-48231 | WordPress Booking Calendar Contact Form plugin <= 1.2.58 - Cross Site Scripting (XSS) Vulnerability | codepeople | Booking Calendar Contact Form | Medium | 6.5 | 2025-07-04 11:18:03 | Deep Dive |
| CVE-2025-6814 | Booking X 1.0 - 1.1.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via export_now() Function | dunskii | Booking X – Appointment and Reservation Availability Calendar | High | 7.5 | 2025-07-04 01:44:04 | Deep Dive |
| CVE-2025-5936 | VR Calendar <= 2.4.7 - Cross-Site Request Forgery to Calendar Sync | innate-images-llc | VR Calendar | Medium | 4.3 | 2025-06-27 07:22:23 | Deep Dive |
| CVE-2025-4667 | Simply Schedule Appointments <= 1.6.8.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes | croixhaug | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | Medium | 6.4 | 2025-06-14 09:23:34 | Deep Dive |
| CVE-2025-48916 | Bookable Calendar - Less critical - Access bypass - SA-CONTRIB-2025-070 | Drupal | Bookable Calendar | - | - | 2025-06-13 15:35:37 | Deep Dive |
| CVE-2025-49468 | Joomla Extension - nobossextensions.com - SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla | nobossextensions.com | No Boss Calendar component for Joomla | - | - | 2025-06-13 09:48:20 | Deep Dive |
| CVE-2025-5144 | The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | stellarwp | The Events Calendar | Medium | 6.4 | 2025-06-11 12:22:52 | Deep Dive |
| CVE-2023-26001 | WordPress Next Event Calendar plugin <= 1.2 - Cross Site Scripting (XSS) Vulnerability | Marchetti Design | Next Event Calendar | Medium | 5.9 | 2025-06-06 12:54:43 | Deep Dive |
| CVE-2025-27360 | WordPress Quick Event Calendar plugin <= 1.4.9 - Cross Site Request Forgery (CSRF) Vulnerability | WP Corner | Quick Event Calendar | Medium | 4.3 | 2025-06-06 12:54:36 | Deep Dive |
| CVE-2025-28958 | WordPress Bg Orthodox Calendar plugin <= 0.13.10 - CSRF to Stored XSS vulnerability | Vadim Bogaiskov | Bg Orthodox Calendar | High | 7.1 | 2025-06-06 12:54:34 | Deep Dive |
| CVE-2025-29003 | WordPress The Holiday Calendar plugin <= 1.18.2.1 - Cross Site Scripting (XSS) Vulnerability | mva7 | The Holiday Calendar | Medium | 6.5 | 2025-06-06 12:54:28 | Deep Dive |
| CVE-2025-49311 | WordPress The Events Calendar Countdown Addon plugin <= 1.4.9 - Cross Site Scripting (XSS) Vulnerability | CoolHappy | The Events Calendar Countdown Addon | Medium | 6.5 | 2025-06-06 12:53:51 | Deep Dive |
| CVE-2025-5733 | Modern Events Calendar <= 7.21.9 - Information Exposure | webnus/ | Modern Events Calendar Lite | Medium | 5.3 | 2025-06-06 03:41:23 | Deep Dive |
| CVE-2025-39372 | WordPress WordPress Events Calendar Registration & Tickets plugin <= 2.6.0 - Reflected Cross Site Scripting (XSS) vulnerability | elbisnero | WordPress Events Calendar Registration & Tickets | High | 7.1 | 2025-05-19 19:38:06 | Deep Dive |
| CVE-2025-47581 | WordPress WordPress Events Calendar Registration & Tickets plugin <= 2.6.0 - PHP Object Injection vulnerability | elbisnero | WordPress Events Calendar Registration & Tickets | Critical | 9.8 | 2025-05-19 18:13:45 | Deep Dive |
| CVE-2025-48246 | WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability | StellarWP | The Events Calendar | Medium | 5.4 | 2025-05-19 14:44:55 | Deep Dive |
| CVE-2025-4669 | Booking Calendar <= 10.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode | wpdevelop | Booking Calendar | Medium | 6.4 | 2025-05-17 11:17:17 | Deep Dive |
| CVE-2025-3527 | EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | EventON | EventON (Pro) - WordPress Virtual Event Calendar Plugin | Medium | 6.4 | 2025-05-17 11:17:16 | Deep Dive |
| CVE-2025-32299 | WordPress QuickCal plugin <= 1.0.15 - Sensitive Data Exposure Vulnerability | Themovation | QuickCal - Appointment Booking Calendar for WordPress | Medium | 4.3 | 2025-05-16 15:45:30 | Deep Dive |
| CVE-2025-32310 | WordPress QuickCal plugin <= 1.0.15 - CSRF to Privilege Escalation vulnerability | ThemeMove | QuickCal - Appointment Booking Calendar for WordPress | High | 8.8 | 2025-05-16 15:45:28 | Deep Dive |