Appointment Booking Calendar

Vendor:

First CVE: Sep 29, 2015 · Active for 10 years

15
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Appointment Booking Calendar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2015
10 years ago
Most Recent CVE
Jul 1, 2026
27 days ago

CVE Severity & Scoring

Appointment Booking Calendar15 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network12 (80.0%)
Unknown2 (13.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High0 (0.0%)
Unknown2 (13.3%)
User Interaction
None8 (53.3%)
Unknown2 (13.3%)
Required5 (33.3%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None9 (60.0%)
Unknown2 (13.3%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then coul
Mar 4, 20207.838NOYES
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to injec
Mar 4, 20204.828NOYES
Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This iss
Apr 22, 20259.827NONO
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.
Nov 18, 20228.827NONO
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
Aug 22, 20199.826NONO
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter
Jul 1, 20264.325NONO
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking
Apr 22, 20258.824NONO
The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actio
Mar 20, 20248.823NONO
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to e
Sep 29, 20157.523NONO
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessabl
Jan 13, 20257.522NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
13.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Appointment Booking Calendar

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.3.1816.11.4%00