CVE-2017-9420

Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sunnythemes:spiffy_calendar:1.0.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.0.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.0.2a:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.0.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.1.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.2.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.3.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:1.3.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:2.0.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:2.0.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:2.1.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:2.1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:2.1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:2.1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.0.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.1.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.1.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.1.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:sunnythemes:spiffy_calendar:3.2.0:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 03:36

Type Values Removed Values Added
References () http://spiffycalendar.sunnythemes.com/version-3-3-0/ - Product, Vendor Advisory () http://spiffycalendar.sunnythemes.com/version-3-3-0/ - Product, Vendor Advisory
References () http://www.securityfocus.com/bid/98931 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/98931 - Third Party Advisory, VDB Entry
References () https://wpvulndb.com/vulnerabilities/8842 - () https://wpvulndb.com/vulnerabilities/8842 -

Information

Published : 2017-06-05 19:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-9420

Mitre link : CVE-2017-9420

CVE.ORG link : CVE-2017-9420


JSON object : View

Products Affected

sunnythemes

  • spiffy_calendar
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')