Booking Calendar Project maintains a focused web-based scheduling application that, despite its narrow product scope, occupies a role in calendar management and booking workflows across deployments. Its vulnerability profile centers on a recurring set of web application weaknesses—cross-site scripting, cross-site request forgery, SQL injection, path traversal, and untrusted deserialization—that are characteristic of calendar and form-handling features common to this class of software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Booking Calendar Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20556HIGH SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter. | Mar 21, 2019 | 8.8 | 47 | NO | YES |
CVE-2022-1463HIGH The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploit | May 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-46914CRITICAL SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtai | Feb 7, 2024 | 9.8 | 26 | NO | NO |
CVE-2018-5673HIGH An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. | Jan 13, 2018 | 8.8 | 26 | NO | NO |
CVE-2021-25040MEDIUM The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross- | Jan 3, 2022 | 6.1 | 22 | NO | NO |
CVE-2017-2151MEDIUM Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 28, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-2150MEDIUM Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. | Apr 28, 2017 | 5.3 | 20 | NO | NO |
CVE-2023-36384MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions. | Jul 18, 2023 | 6.1 | 18 | NO | NO |
CVE-2018-5672MEDIUM An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter. | Jan 13, 2018 | 4.8 | 18 | NO | NO |
CVE-2018-5671MEDIUM An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter. | Jan 13, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Booking Calendar Project.
Media articles that mention a CVE ID that affects a product developed by Booking Calendar Project — matched by CVE ID, not by vendor name.