Acal maintains a calendar and scheduling application with a narrow product footprint that has drawn vulnerability attention over a limited scope of reported issues. The observed weaknesses cluster around miscellaneous or unclassified categories, reflecting the limited granularity available in early or sparse disclosures for this vendor; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acal over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2261HIGH PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | May 9, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-0182HIGH login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside". | Jan 12, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-0183MEDIUM Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which | Jan 12, 2006 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acal.
Media articles that mention a CVE ID that affects a product developed by Acal — matched by CVE ID, not by vendor name.