Vulnerabilities (CVE)

Filtered by vendor Wpdevart Subscribe
Filtered by product Booking Calendar
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47428 1 Wpdevart 1 Booking Calendar 2024-09-05 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.
CVE-2022-47438 1 Wpdevart 1 Booking Calendar 2024-02-04 N/A 5.4 MEDIUM
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.
CVE-2023-24388 1 Wpdevart 1 Booking Calendar 2024-02-04 N/A 5.4 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).
CVE-2022-3982 1 Wpdevart 1 Booking Calendar 2024-02-04 N/A 9.8 CRITICAL
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
CVE-2018-10363 1 Wpdevart 1 Booking Calendar 2024-02-04 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.