Webcalendar

Vendor:

First CVE: Jun 27, 2001 · Active for 25 years

28
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Webcalendar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Jan 25, 2024
915 days ago

CVE Severity & Scoring

Webcalendar28 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (25.0%)
Unknown21 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (25.0%)
High0 (0.0%)
Unknown21 (75.0%)
User Interaction
None4 (14.3%)
Unknown21 (75.0%)
Required3 (10.7%)
Privileges Required
Low2 (7.1%)
High1 (3.6%)
None4 (14.3%)
Unknown21 (75.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
Jan 27, 20209.887NOYES
Local file inclusion in WebCalendar before 1.2.5.
Jan 27, 20208.838NOYES
CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret p
Dec 4, 20055.025NOYES
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme
Oct 11, 20127.523NONO
Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
Jan 13, 20235.420NONO
Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Aug 29, 20176.120NONO
includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary glob
Mar 8, 20077.520NONO
Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid
Dec 1, 20057.520NONO
PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php
Aug 29, 20057.520NONO
Vulnerability in WebCalendar 0.9.26 allows remote command execution.
Jun 27, 20017.520NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
14.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Webcalendar

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.3.016.10.5%00
1.2.725.51.6%00
1.2.614.31.2%00
1.2.417.52.2%00
1.2.325.91.7%00
1.2.225.91.7%00
1.2.125.91.7%00
1.2.025.91.7%00
1.225.91.7%00
1.1.634.61.7%01
1.1.525.91.7%00
1.1.425.91.7%00
1.1.325.91.7%00
1.1.225.91.7%00
1.1.125.91.7%00
1.1.015.02.3%00
1.0.427.21.8%00
1.0.336.32.0%00
1.0.226.31.9%00
1.0.166.32.7%01