VendorsMF Gig Calendar Projectmf_gig_calendarall versions
Vulnerabilities

MF Gig Calendar Project MF Gig Calendar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-50842
WordPress MF Gig Calendar Plugin <= 1.2.1 is vulnerable to SQL Injection
Published 2023-12-28 · Modified
8.8EPSS 0.005
CVE-2024-33651
WordPress MF Gig Calendar plugin <= 1.2.1 - Cross Site Request Forgery (CSRF) vulnerability
Published 2024-04-26 · Modified
8.8EPSS 0.002
CVE-2024-3756
MF Gig Calendar <= 1.2.1 - Arbitrary Event Deletion via CSRF
Published 2024-05-06 · Analyzed
7.5EPSS 0.003
CVE-2023-37970
WordPress MF Gig Calendar Plugin <= 1.2 is vulnerable to Cross Site Scripting (XSS)
Published 2023-07-27 · Modified
6.5EPSS 0.004
CVE-2021-24510
MF Gig Calendar < 1.2 - Reflected Cross-Site Scripting (XSS)
Published 2021-09-13 · Modified
6.1EPSS 0.027
CVE-2024-3755
MF Gig Calendar <= 1.2.1 - Editor+ Stored XSS
Published 2024-05-06 · Analyzed
5.4EPSS 0.004
CVE-2012-4242
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.
Published 2012-10-01 · Modified
4.31 PoCEPSS 0.093