Webcalendar

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 21
    Known Exploited: 0
    0
    Critical Level Threats
    9
    High Level Threats
    11
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2008-1954

    SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Last Modified: Apr 23, 2026
    Published: Apr 25, 2008

    CVE-2007-6696

    Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1 requires user authentication.

    Last Modified: Apr 23, 2026
    Published: Feb 01, 2008

    CVE-2007-1343

    includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.

    Last Modified: Apr 23, 2026
    Published: Mar 08, 2007

    CVE-2006-6669

    Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter.

    Last Modified: Apr 23, 2026
    Published: Dec 20, 2006

    CVE-2006-2762

    PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter, which is remotely accessed in an fopen call whose results are used to define a user_inc setting that is used in an include_once call.

    Last Modified: Apr 16, 2026
    Published: Jun 02, 2006
    Items Per Page
    Webcalendar Vulnerabilities & Security CVEs | CVE-DB