Vulnerabilities (CVE)

Filtered by vendor Codepeople Subscribe
Filtered by product Appointment Booking Calendar
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-7319 1 Codepeople 1 Appointment Booking Calendar 2018-10-09 7.5 HIGH N/A
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
CVE-2015-7320 1 Codepeople 1 Appointment Booking Calendar 2018-10-09 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.