Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Booking Calendar Project

First CVE: Apr 28, 2017Active for: 9 yearsTotal CVEs: 11
38.9
VTI Score
Medium

Booking Calendar Project maintains a focused web-based scheduling application that, despite its narrow product scope, occupies a role in calendar management and booking workflows across deployments. Its vulnerability profile centers on a recurring set of web application weaknesses—cross-site scripting, cross-site request forgery, SQL injection, path traversal, and untrusted deserialization—that are characteristic of calendar and form-handling features common to this class of software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Booking Calendar Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2017
9 years ago
Most Recent CVE
Feb 7, 2024
902 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-20556HIGH
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
Mar 21, 20198.847NOYES
CVE-2022-1463HIGH
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploit
May 10, 20228.828NONO
CVE-2023-46914CRITICAL
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtai
Feb 7, 20249.826NONO
CVE-2018-5673HIGH
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.
Jan 13, 20188.826NONO
CVE-2021-25040MEDIUM
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-
Jan 3, 20226.122NONO
CVE-2017-2151MEDIUM
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Apr 28, 20176.121NONO
CVE-2017-2150MEDIUM
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
Apr 28, 20175.320NONO
CVE-2023-36384MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
Jul 18, 20236.118NONO
CVE-2018-5672MEDIUM
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.
Jan 13, 20184.818NONO
CVE-2018-5671MEDIUM
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter.
Jan 13, 20184.818NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
27%
9%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low2 (18.2%)
High3 (27.3%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Booking Calendar Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Booking Calendar Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Booking Calendar Project's Products

View all 5 CNAs →

Top CWEs