VendorsDiscoursecalendarall versions
Vulnerabilities

Discourse Calendar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-26145
Uninvited user is able to join and mark the attendance of the the private event
Published 2024-02-21 · Analyzed
6.5EPSS 0.004
CVE-2024-45303
Discourse Calendar plugin event names susceptible to XSS
Published 2024-09-12 · Analyzed
6.1EPSS 0.003
CVE-2022-41913
Discourse-calendar exposes members of hidden groups
Published 2022-11-14 · Modified
5.4EPSS 0.004
CVE-2024-24817
User can see invitees in events created in PMs and private categories
Published 2024-02-22 · Analyzed
5.3EPSS 0.004