CVE-2022-36371 – My Calendar <= 3.3.16 - Open Redirect
https://notcve.org/view.php?id=CVE-2022-36371
The My Calendar plugin for WordPress is vulnerable to Open Redirection in versions up to, and including, 3.3.16. This makes it possible for unauthenticated attackers to create links that look to be part of an affected site, but will redirect to the attacker's target. This vulnerability can be utilized for malicious redirection and can also be used for phishing. • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2021-24927 – My Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24927
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue El plugin My Calendar de WordPress versiones anteriores a 3.2.18, no sanea y escapa del parámetro callback de la acción AJAX mc_post_lookup (disponible para cualquier usuario autenticado) antes de devolverlo a la respuesta, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/86f3acc7-8902-4215-bd75-6105d601524e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-15713 – My Calendar <= 3.1.9 - Unauthenticated Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2019-15713
The my-calendar plugin before 3.1.10 for WordPress has XSS. El plugin my-calendar versiones anteriores a 3.1.0 para WordPress, tiene una vulnerabilidad de tipo XSS. • https://wordpress.org/plugins/my-calendar/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-6527 – My Calendar < 1.10.5 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-6527
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. Cross-site scripting (XSS) en el plug-in My Calendar antes de v1.10.2 para WordPress permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del PATH_INFO. Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. • http://plugins.trac.wordpress.org/changeset/490070/my-calendar http://secunia.com/advisories/47579 http://wordpress.org/extend/plugins/my-calendar/changelog http://www.securityfocus.com/bid/51539 https://exchange.xforce.ibmcloud.com/vulnerabilities/72454 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2002-1626
https://notcve.org/view.php?id=CVE-2002-1626
Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL. • http://securitytracker.com/id?1003256 http://www.kb.cert.org/vuls/id/806091 http://www.securityfocus.com/bid/3856 https://exchange.xforce.ibmcloud.com/vulnerabilities/7966 •