Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webcalendar Project

First CVE: Jun 27, 2001Active for: 25 yearsTotal CVEs: 31
42.3
VTI Score
High

Webcalendar Project maintains a narrowly scoped web-based calendar application that, despite modest CVE volume, occupies a notable position among calendar and scheduling software in enterprise and community deployments. Its vulnerability profile concentrates on web-application input-handling issues—cross-site scripting, injection flaws, path traversal, and observable discrepancies—that are typical of server-side PHP applications handling user-supplied calendar data and file paths, and the vendor's disclosures have an elevated tendency toward public exploit availability. Defenders should prioritize patching this application where it is internet-reachable or processes untrusted calendar input; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 92% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webcalendar Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Jan 25, 2024
911 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1495CRITICAL
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
Jan 27, 20209.887NOYES
CVE-2012-1496HIGH
Local file inclusion in WebCalendar before 1.2.5.
Jan 27, 20208.838NOYES
CVE-2008-1954HIGH
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
Apr 25, 20087.528NOYES
CVE-2005-3982MEDIUM
CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret p
Dec 4, 20055.025NOYES
CVE-2004-1510HIGH
WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.
Dec 31, 20047.524NONO
CVE-2012-5385HIGH
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme
Oct 11, 20127.523NONO
CVE-2023-0289MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
Jan 13, 20235.420NONO
CVE-2017-10840MEDIUM
Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Aug 29, 20176.120NONO
CVE-2007-1343HIGH
includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary glob
Mar 8, 20077.520NONO
CVE-2005-3949HIGH
Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid
Dec 1, 20057.520NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
58%
35%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (22.6%)
Unknown24 (77.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (22.6%)
High0 (0.0%)
Unknown24 (77.4%)
User Interaction
None4 (12.9%)
Unknown24 (77.4%)
Required3 (9.7%)
Privileges Required
Low2 (6.5%)
High1 (3.2%)
None4 (12.9%)
Unknown24 (77.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.2% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
16.1% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webcalendar Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webcalendar Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webcalendar Project's Products

View all 4 CNAs →

Top CWEs