CVE-2016-10916
- EPSS 1.82%
- Veröffentlicht 22.08.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 02:45:04
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
CVE-2019-14791
- EPSS 1.39%
- Veröffentlicht 09.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:21
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
CVE-2015-7320
- EPSS 2.14%
- Veröffentlicht 29.09.2015 19:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecif...
CVE-2015-7319
- EPSS 2.43%
- Veröffentlicht 29.09.2015 19:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updat...