Appointment Booking Calendar
Vendor:
First CVE: Sep 29, 2015 · Active for 10 years
15
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Appointment Booking Calendar over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2015
10 years ago
Most Recent CVE
Jul 1, 2026
27 days ago
CVE Severity & Scoring
Appointment Booking Calendar15 CVEs
47%
40%
13%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network12 (80.0%)
Unknown2 (13.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High0 (0.0%)
Unknown2 (13.3%)
User Interaction
None8 (53.3%)
Unknown2 (13.3%)
Required5 (33.3%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None9 (60.0%)
Unknown2 (13.3%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9372HIGH The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then coul | Mar 4, 2020 | 7.8 | 38 | NO | YES |
CVE-2020-9371MEDIUM Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to injec | Mar 4, 2020 | 4.8 | 28 | NO | YES |
CVE-2025-46247CRITICAL Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This iss | Apr 22, 2025 | 9.8 | 27 | NO | NO |
CVE-2022-43482HIGH Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. | Nov 18, 2022 | 8.8 | 27 | NO | NO |
CVE-2016-10916CRITICAL The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319. | Aug 22, 2019 | 9.8 | 26 | NO | NO |
CVE-2026-12113MEDIUM The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter | Jul 1, 2026 | 4.3 | 25 | NO | NO |
CVE-2025-46241HIGH Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking | Apr 22, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-0856HIGH The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actio | Mar 20, 2024 | 8.8 | 23 | NO | NO |
CVE-2015-7319HIGH SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to e | Sep 29, 2015 | 7.5 | 23 | NO | NO |
CVE-2024-12274HIGH The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessabl | Jan 13, 2025 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
13.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Appointment Booking Calendar
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.18 | 1 | 6.1 | 1.4% | 0 | 0 |