Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Booking calendar, Appointment Booking System — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Booking calendar, Appointment Booking System, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page collects security advisories for the Appointment Booking System, a commercial calendar and scheduling application. It aggregates known flaws within this specific software product, covering a defined historical period to document its security evolution. Visitors can track the vendor's disclosed advisories, analyze the distribution of weakness classes such as injection or authentication failures, and review the product's cumulative vulnerability history to assess its current security posture and remediation trends.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-14334 Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload - - 2026-08-19
CVE-2026-73395 WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2026-08-18
CVE-2026-8840 Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action CWE-862 5.3 Medium 2026-08-15
CVE-2026-57778 WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-07-13
CVE-2026-15289 Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id' CWE-89 5.9 Medium 2026-07-10
CVE-2026-25435 WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-03-25
CVE-2025-67574 WordPress Booking calendar, Appointment Booking System plugin <= 3.2.30 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-12-09
CVE-2024-12077 Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id' CWE-79 6.1 Medium 2025-01-07
CVE-2024-10856 Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection CWE-89 6.5 Medium 2024-12-24
CVE-2023-24407 WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability CWE-862 5.0 Medium 2024-12-09
CVE-2024-9504 Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload CWE-434 7.2 High 2024-11-26
CVE-2023-24373 WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability CWE-472 3.7 Low 2024-06-03
CVE-2022-47428 WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injection CWE-89 6.7 Medium 2023-11-06
CVE-2022-47438 WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-03-29
CVE-2023-24388 WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-02-17
CVE-2022-3982 Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload 9.8 - 2022-12-12

All 16 known CVE vulnerabilities affecting Booking calendar, Appointment Booking System with full Chinese analysis, references, and POCs where available.