CVE Tools

Booking-calendar-project

4 CVEs tracked since 2018. Since Jan 2018, none of them reached CISA KEV.

Booking-calendar-project CVEs per month

Jan 2018 to Jan 2018. Point at a month, or focus the strip and use the arrow keys.
Booking-calendar-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0140

Products

The products that kept showing up in Booking-calendar-project's monthly top three, with their CVEs summed over those months.

  1. Booking Calendar41 month

Latest CVEs

The 10 most recently published vulnerabilities affecting Booking-calendar-project.

  1. CVE-2023-36384WordPress Booking Calendar Contact Form Plugin <= 1.2.40 is vulnerable to Cross Site Scripting (XSS)7.1
  2. CVE-2022-1463Booking Calendar <= 9.1 - PHP Object Injection via Shortcode8.8
  3. CVE-2021-25040Booking Calendar < 8.9.2 - Reflected Cross-Site Scripting6.1
  4. CVE-2018-20556SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.8.8
  5. CVE-2018-5673An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.8.8
  6. CVE-2018-5671An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter.4.8
  7. CVE-2018-5670An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter.4.8
  8. CVE-2018-5672An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.4.8
  9. CVE-2017-2150Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.5.3
  10. CVE-2017-2151Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.6.1

The record

Peak rank
#73 in Jan 2018
Busiest month shown
Jan 2018, 4 CVEs
Months with a KEV entry
0 since Jan 2018
Monthly snapshots
1 since 2018
Booking-calendar-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store