Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

K5n

First CVE: Mar 16, 2007Active for: 19 yearsTotal CVEs: 8

K5n develops WebCalendar, a web-based calendar and scheduling application whose vulnerability footprint centers on web application input-handling and access-control weaknesses such as cross-site scripting, cross-site request forgery, code injection, and exposure of sensitive information. The product's web-facing role and recurrent weaknesses in input neutralization and request validation reflect the parser and rendering demands of a calendar interface that processes user-supplied data and state changes. Public exploit tooling has accompanied vulnerabilities in this product line; defenders should treat WebCalendar instances as requiring careful inventory and timely patching, particularly where exposed to untrusted networks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by K5n over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2007
19 years ago
Most Recent CVE
Nov 15, 2024
617 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-1483HIGH
Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php
Mar 16, 20077.531NOYES
CVE-2008-2836HIGH
PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a
Jun 24, 20087.529NOYES
CVE-2010-0637MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administrat
Feb 12, 20106.821NONO
CVE-2010-0638MEDIUM
Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrat
Feb 15, 20106.820NONO
CVE-2012-0846MEDIUM
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable.
Oct 8, 20124.318NONO
CVE-2011-3814MEDIUM
WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path
Sep 24, 20115.017NONO
CVE-2024-1097MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new repor
Nov 15, 20245.416NONO
CVE-2010-0636MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1)
Feb 12, 20104.316NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
25%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (12.5%)
Unknown7 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High0 (0.0%)
Unknown7 (87.5%)
User Interaction
None0 (0.0%)
Unknown7 (87.5%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (87.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by K5n.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by K5n — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For K5n's Products

View all 3 CNAs →

Top CWEs