Calendarscript is a narrowly scoped calendar application with a minimal but notable disclosure footprint. The observed weakness classifications remain broad placeholders in available records, making it difficult to isolate durable patterns; live vulnerability details and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Calendarscript over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1148MEDIUM calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug inf | May 2, 2005 | 5.0 | 16 | NO | NO |
CVE-2005-1145MEDIUM NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web sc | Apr 12, 2005 | 4.3 | 15 | NO | NO |
CVE-2005-1147MEDIUM calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and de | Apr 12, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-1146MEDIUM NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to in | Apr 12, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Calendarscript.
Media articles that mention a CVE ID that affects a product developed by Calendarscript — matched by CVE ID, not by vendor name.