Webcalendar
Vendor:
First CVE: Jun 27, 2001 · Active for 25 years
28
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webcalendar over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Jan 25, 2024
915 days ago
CVE Severity & Scoring
Webcalendar28 CVEs
61%
32%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (25.0%)
Unknown21 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (25.0%)
High0 (0.0%)
Unknown21 (75.0%)
User Interaction
None4 (14.3%)
Unknown21 (75.0%)
Required3 (10.7%)
Privileges Required
Low2 (7.1%)
High1 (3.6%)
None4 (14.3%)
Unknown21 (75.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1495CRITICAL install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. | Jan 27, 2020 | 9.8 | 87 | NO | YES |
CVE-2012-1496HIGH Local file inclusion in WebCalendar before 1.2.5. | Jan 27, 2020 | 8.8 | 38 | NO | YES |
CVE-2005-3982MEDIUM CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret p | Dec 4, 2005 | 5.0 | 25 | NO | YES |
CVE-2012-5385HIGH install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme | Oct 11, 2012 | 7.5 | 23 | NO | NO |
CVE-2023-0289MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master. | Jan 13, 2023 | 5.4 | 20 | NO | NO |
CVE-2017-10840MEDIUM Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | Aug 29, 2017 | 6.1 | 20 | NO | NO |
CVE-2007-1343HIGH includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary glob | Mar 8, 2007 | 7.5 | 20 | NO | NO |
CVE-2005-3949HIGH Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid | Dec 1, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-2717HIGH PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php | Aug 29, 2005 | 7.5 | 20 | NO | NO |
CVE-2001-0477HIGH Vulnerability in WebCalendar 0.9.26 allows remote command execution. | Jun 27, 2001 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
14.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Webcalendar
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.0 | 1 | 6.1 | 0.5% | 0 | 0 |
| 1.2.7 | 2 | 5.5 | 1.6% | 0 | 0 |
| 1.2.6 | 1 | 4.3 | 1.2% | 0 | 0 |
| 1.2.4 | 1 | 7.5 | 2.2% | 0 | 0 |
| 1.2.3 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.2.2 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.2.1 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.2.0 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.2 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.1.6 | 3 | 4.6 | 1.7% | 0 | 1 |
| 1.1.5 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.1.4 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.1.3 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.1.2 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.1.1 | 2 | 5.9 | 1.7% | 0 | 0 |
| 1.1.0 | 1 | 5.0 | 2.3% | 0 | 0 |
| 1.0.4 | 2 | 7.2 | 1.8% | 0 | 0 |
| 1.0.3 | 3 | 6.3 | 2.0% | 0 | 0 |
| 1.0.2 | 2 | 6.3 | 1.9% | 0 | 0 |
| 1.0.1 | 6 | 6.3 | 2.7% | 0 | 1 |