My Calendar Project maintains a web-based calendar application whose vulnerability profile centers on application-layer defects typical of form-handling and page-generation code, specifically cross-site request forgery and cross-site scripting weaknesses. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by My Calendar Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15713MEDIUM The my-calendar plugin before 3.1.10 for WordPress has XSS. | Aug 28, 2019 | 6.1 | 29 | NO | YES |
CVE-2023-23813HIGH Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions. | May 22, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-47427HIGH Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. | Mar 15, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-24927MEDIUM The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before ou | Nov 29, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by My Calendar Project.
Media articles that mention a CVE ID that affects a product developed by My Calendar Project — matched by CVE ID, not by vendor name.