Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wpdevart Subscribe
Filtered by product Booking Calendar
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24388 1 Wpdevart 1 Booking Calendar 2023-02-27 N/A 5.4 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).
CVE-2022-3982 1 Wpdevart 1 Booking Calendar 2022-12-14 N/A 9.8 CRITICAL
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
CVE-2018-10363 1 Wpdevart 1 Booking Calendar 2018-08-09 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.