Mf Gig Calendar Project Mf Gig Calendar vulnerabilities
7 known vulnerabilities affecting mf_gig_calendar_project/mf_gig_calendar.
Total CVEs
7
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2024-3756HIGHCVSS 7.5≤ 1.2.12024-05-06
CVE-2024-3756 [HIGH] CWE-352 CVE-2024-3756: The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which c
The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack
nvd
CVE-2024-3755MEDIUMCVSS 5.4≤ 1.2.12024-05-06
CVE-2024-3755 [MEDIUM] CWE-79 CVE-2024-3755: The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings
The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
nvd
CVE-2024-33651HIGHCVSS 8.8≤ 1.2.12024-04-26
CVE-2024-33651 [HIGH] CWE-352 CVE-2024-33651: Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects
Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1.
nvd
CVE-2023-50842HIGHCVSS 8.8≤ 1.2.12023-12-28
CVE-2023-50842 [HIGH] CWE-89 CVE-2023-50842: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1.
nvd
CVE-2023-37970MEDIUMCVSS 5.4fixed in 1.2.12023-07-27
CVE-2023-37970 [MEDIUM] CWE-79 CVE-2023-37970: Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Matthew Fries MF Gig Calenda
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Matthew Fries MF Gig Calendar plugin <= 1.2 versions.
nvd
CVE-2021-24510MEDIUMCVSS 6.1PoC≤ 1.12021-09-13
CVE-2021-24510 [MEDIUM] CWE-79 CVE-2021-24510: The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter be
The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue
nvd
CVE-2012-4242MEDIUMCVSS 4.3PoCv0.9.22012-10-01
CVE-2012-4242 [MEDIUM] CWE-79 CVE-2012-4242: Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows re
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.
nvd