K5n develops WebCalendar, a web-based calendar and scheduling application whose vulnerability footprint centers on web application input-handling and access-control weaknesses such as cross-site scripting, cross-site request forgery, code injection, and exposure of sensitive information. The product's web-facing role and recurrent weaknesses in input neutralization and request validation reflect the parser and rendering demands of a calendar interface that processes user-supplied data and state changes. Public exploit tooling has accompanied vulnerabilities in this product line; defenders should treat WebCalendar instances as requiring careful inventory and timely patching, particularly where exposed to untrusted networks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by K5n over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1483HIGH Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php | Mar 16, 2007 | 7.5 | 31 | NO | YES |
CVE-2008-2836HIGH PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a | Jun 24, 2008 | 7.5 | 29 | NO | YES |
CVE-2010-0637MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administrat | Feb 12, 2010 | 6.8 | 21 | NO | NO |
CVE-2010-0638MEDIUM Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrat | Feb 15, 2010 | 6.8 | 20 | NO | NO |
CVE-2012-0846MEDIUM Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable. | Oct 8, 2012 | 4.3 | 18 | NO | NO |
CVE-2011-3814MEDIUM WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2024-1097MEDIUM A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new repor | Nov 15, 2024 | 5.4 | 16 | NO | NO |
CVE-2010-0636MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) | Feb 12, 2010 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by K5n.
Media articles that mention a CVE ID that affects a product developed by K5n — matched by CVE ID, not by vendor name.