Webcalendar is a web-based calendar application with a small but persistent vulnerability footprint centered on its core product and a closely related professional variant. The recurring weakness classes—SQL injection, cross-site scripting, and related input-handling flaws—are characteristic of web applications that parse and display user-supplied data without sufficient sanitization, and the vendor's disclosures frequently acquire public exploit code. Defenders deploying this application should treat input validation and output encoding as critical hardening points and prioritize patching releases that address these application-layer weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webcalendar over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1495CRITICAL install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. | Jan 27, 2020 | 9.8 | 87 | NO | YES |
CVE-2012-1496HIGH Local file inclusion in WebCalendar before 1.2.5. | Jan 27, 2020 | 8.8 | 38 | NO | YES |
CVE-2008-1954HIGH SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | Apr 25, 2008 | 7.5 | 28 | NO | YES |
CVE-2005-3982MEDIUM CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret p | Dec 4, 2005 | 5.0 | 25 | NO | YES |
CVE-2004-1510HIGH WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php. | Dec 31, 2004 | 7.5 | 24 | NO | NO |
CVE-2012-5385HIGH install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme | Oct 11, 2012 | 7.5 | 23 | NO | NO |
CVE-2023-0289MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master. | Jan 13, 2023 | 5.4 | 20 | NO | NO |
CVE-2017-10840MEDIUM Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | Aug 29, 2017 | 6.1 | 20 | NO | NO |
CVE-2007-1343HIGH includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary glob | Mar 8, 2007 | 7.5 | 20 | NO | NO |
CVE-2005-3949HIGH Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid | Dec 1, 2005 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webcalendar.
Media articles that mention a CVE ID that affects a product developed by Webcalendar — matched by CVE ID, not by vendor name.