VendorsWebCalendar Projectwebcalendarany version
Vulnerabilities

WebCalendar Project WebCalendar any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2012-1495
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
Published 2020-01-27 · Modified
9.82 PoCEPSS 0.798
CVE-2012-1496
Local file inclusion in WebCalendar before 1.2.5.
Published 2020-01-27 · Modified
8.81 PoCEPSS 0.025
CVE-2023-0289
Cross-site Scripting (XSS) - Stored in craigk5n/webcalendar
Published 2023-01-13 · Modified
7.6EPSS 0.005
CVE-2013-1422
webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
Published 2020-02-04 · Modified
5.3EPSS 0.016
CVE-2013-1421
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.
Published 2014-04-22 · Modified
4.3EPSS 0.012
CVE-2012-5384
Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5) $ext_users[] variables in view_entry.php, different vectors than CVE-2012-0846.
Published 2012-10-11 · Modified
4.3EPSS 0.009