CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-39601 LOW

WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability

CVSS 3.7 EPSS n/a Oct 2, 2026
CVE-2026-93655 MEDIUM

Booking Calendar <= 11.8.3 - Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter

CVSS 6.1 EPSS 0.37% Sep 22, 2026
CVE-2026-92561 MEDIUM

Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameter

CVSS 6.1 EPSS 0.41% Sep 18, 2026
CVE-2026-92619 HIGH

Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter

CVSS 7.2 EPSS 0.66% Sep 18, 2026
CVE-2026-74002 MEDIUM

WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability

CVSS 5.3 EPSS 0.29% Sep 17, 2026
CVE-2026-59558 HIGH

WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Jul 27, 2026
CVE-2026-42751 MEDIUM

WordPress Booking Manager plugin <= 2.1.18 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.22% May 27, 2026
CVE-2026-32358 HIGH

WordPress Booking Calendar plugin <= 10.14.15 - SQL Injection vulnerability

CVSS 7.6 EPSS 0.38% Mar 13, 2026
CVE-2026-2230 MEDIUM

Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification

CVSS 4.3 EPSS 0.20% Feb 18, 2026
CVE-2026-1431 MEDIUM

Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure

CVSS 5.3 EPSS 0.30% Jan 31, 2026
CVE-2025-14982 MEDIUM

Booking Calendar <= 10.14.11 - Missing Authorization to Sensitive Information Exposure

CVSS 4.3 EPSS 0.38% Jan 16, 2026
CVE-2025-14146 MEDIUM

Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure

CVSS 5.3 EPSS 0.38% Jan 9, 2026
CVE-2025-14383 HIGH

Booking Calendar <= 10.14.8 - Unauthenticated SQL Injection via dates_to_check

CVSS 7.5 EPSS 0.42% Dec 15, 2025
CVE-2025-12804 MEDIUM

Booking Calendar <= 10.14.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode

CVSS 6.4 EPSS 0.18% Dec 5, 2025
CVE-2025-64381 MEDIUM

WordPress Booking Calendar plugin <= 10.14.7 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.15% Nov 13, 2025
CVE-2025-64275 MEDIUM

WordPress Booking Manager plugin <= 2.1.17 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.15% Nov 13, 2025
CVE-2025-9346 MEDIUM

Booking Calendar <= 10.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVSS 6.4 EPSS 0.20% Aug 28, 2025
CVE-2025-4669 MEDIUM

Booking Calendar <= 10.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode

CVSS 6.4 EPSS 0.34% May 17, 2025
CVE-2024-13821 MEDIUM

WP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking Manipulation

CVSS 5.3 EPSS 0.41% Feb 12, 2025
CVE-2024-13323 MEDIUM

Booking Calendar <= 10.9.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'booking' Shortcode

CVSS 6.4 EPSS 0.39% Jan 14, 2025
CVE-2024-11945 MEDIUM

Email Reminders <= 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

CVSS 6.4 EPSS 0.35% Dec 10, 2024
CVE-2024-9306 MEDIUM

WP Booking Calendar <= 10.6 - Authenticated (Admin+) Stored Cross-Site Scripting

CVSS 4.8 EPSS 0.32% Oct 4, 2024
CVE-2024-8274 MEDIUM

WP Booking Calendar <= 10.5 - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 0.50% Aug 30, 2024
CVE-2024-6930 MEDIUM

WP Booking Calendar <= 10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingform Shortcode

CVSS 6.4 EPSS 0.32% Jul 24, 2024
CVE-2024-1207 CRITICAL

Booking Calendar <= 9.9 - Unauthenticated SQL Injection

CVSS 9.8 EPSS 3.15% Feb 8, 2024

Showing 1 to 25 CVEs · page 1 (more available)