PHP Calendar is a modestly represented web-based calendar application that presents a focused but notable vulnerability footprint within its narrow product scope. The recurring exposure reflects input-handling and application-layer weaknesses characteristic of web applications, though the specific recurrence pattern is not yet distinctly defined. Current exploitation activity, severity distribution, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Calendar over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1423HIGH Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, | Dec 31, 2004 | 7.5 | 42 | NO | YES |
CVE-2009-3702HIGH Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via a full pathname in the configfile param | Dec 22, 2009 | 7.5 | 28 | NO | YES |
CVE-2022-4455MEDIUM A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] | Dec 13, 2022 | 6.1 | 22 | NO | NO |
CVE-2017-6485MEDIUM A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed | Mar 5, 2017 | 6.1 | 21 | NO | NO |
CVE-2005-1397HIGH SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | May 3, 2005 | 7.5 | 20 | NO | NO |
CVE-2010-2041MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) descript | May 25, 2010 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Calendar.
Media articles that mention a CVE ID that affects a product developed by Php Calendar — matched by CVE ID, not by vendor name.