Elbtide maintains a narrowly scoped product portfolio centered on its Advanced Booking Calendar, a web-facing appointment and scheduling application whose vulnerabilities skew strongly toward critical severity and frequently acquire public exploit code. The exposure concentrates on application-layer input-handling and state-management weaknesses, particularly cross-site scripting, SQL injection, and cross-site request forgery flaws that are endemic to calendar and form-processing interfaces. Defenders should prioritize patching instances of this product given the combination of critical-severity tendency and public exploit availability; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elbtide over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45822CRITICAL Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | Dec 5, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-0694CRITICAL The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCale | Mar 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-1007MEDIUM The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross | Apr 11, 2022 | 6.1 | 25 | NO | YES |
CVE-2022-45824MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | Dec 5, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-1006HIGH The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as adm | Apr 11, 2022 | 7.2 | 19 | NO | NO |
CVE-2021-24232MEDIUM The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cros | Apr 22, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24225MEDIUM The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a | Apr 12, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elbtide.
Media articles that mention a CVE ID that affects a product developed by Elbtide — matched by CVE ID, not by vendor name.