Codewalkers' disclosed vulnerabilities center on the LTWCalendar product, a calendar component with a footprint more prominent than typical for its scope, and surface around input-handling weaknesses including SQL injection. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codewalkers over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4011HIGH SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to execute arbitrary SQL commands vi | Dec 5, 2005 | 7.5 | 30 | NO | YES |
CVE-2006-3041HIGH PHP remote file inclusion vulnerability in Ltwcalendar/calendar.php in Codewalkers Ltwcalendar 4.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the ltw_conf | Jun 15, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-6228MEDIUM Cross-site scripting (XSS) vulnerability in Codewalkers ltwCalendar (aka PHP Event Calendar) before 4.2.1 allows remote attackers to inject arbitrary HTML or web script via unknown | Dec 2, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-6229MEDIUM Codewalkers ltwCalendar (aka PHP Event Calendar) before 4.2.1 logs failed passwords, which might allow attackers to infer correct passwords from the log file. | Dec 2, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codewalkers.
Media articles that mention a CVE ID that affects a product developed by Codewalkers — matched by CVE ID, not by vendor name.