Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical1
High1
Medium3
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2024-11-21

CVE-2022-1006 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks

PLUGIN Advanced Booking Calendar

CVE-2022-1006

HIGH CVSS 7.2 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1007 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Advanced Booking Calendar

CVE-2022-1007

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0694 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Advanced Booking Calendar

CVE-2022-0694

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2021-24232 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue

PLUGIN Advanced Booking Calendar

CVE-2021-24232

MEDIUM CVSS 5.4 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24225 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue

PLUGIN Advanced Booking Calendar

CVE-2021-24225

MEDIUM CVSS 5.4 2021-04-12
Scroll to top