Calendar

44 known CVEs 4K+ active installs

Scan My Site Free

UNKNOWN: 44
Known Vulnerabilities 44
CVE-2026-45286 UNKNOWN EPSS 0.2%
Published 2026-06-01 · Affected: *
Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance b
CVE-2026-45286 UNKNOWN EPSS 0.2%
Published 2026-06-01 · Affected: *
Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance b
CVE-2026-29052 UNKNOWN
Published 2026-03-05 · Affected: *
The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cros
CVE-2025-14548 UNKNOWN EPSS 0.1%
Published 2025-12-23 · Affected: *
The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all versions up to, and including, 1.3.16 due to insufficient input sanitization and ou
CVE-2025-66550 UNKNOWN EPSS 0.3%
Published 2025-12-05 · Affected: *
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the s
CVE-2025-66550 UNKNOWN EPSS 0.3%
Published 2025-12-05 · Affected: *
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the s
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: <6.0.0
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: <6.0.0
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: <6.0.0
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: <6.0.0
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: *
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: *
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: <6.0.0
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: <6.0.0
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66546 UNKNOWN
Published 2025-12-05 · Affected: <6.0.0
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. Th
CVE-2025-66511 UNKNOWN EPSS 0.2%
Published 2025-12-05 · Affected: *
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid par
CVE-2024-2831 UNKNOWN EPSS 0.5%
Published 2024-05-02 · Affected: *
The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and including, 1.3.14 due to insufficient escaping on the user supplied parameter an
CVE-2017-15891 UNKNOWN EPSS 0.6%
Published 2017-12-08 · Affected: *
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.1
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.x-dev
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.1
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.x-dev
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr
CVE-2009-3157 UNKNOWN EPSS 0.6%
Published 2009-09-10 · Affected: <6.x-2.0
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web scr

Is Calendar running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free