Codepeople
Codepeople Booking Calendar Contact Form: vulnerabilidades y CVE
Codepeople Booking Calendar Contact Form tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6810 | Media (5.3) | 0.43% | — | 24 abr 2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing… |
| CVE-2025-13318 | Media (5.3) | 0.30% | — | 22 nov 2025 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the… |
| CVE-2025-48231 | Media (6.5) | 0.23% | — | 4 jul 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking… |
| CVE-2025-24723 | Media (5.9) | 0.31% | — | 24 ene 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking… |
| CVE-2023-25037 | Media (4.3) | 0.56% | — | 9 dic 2024 | Missing Authorization vulnerability in CodePeople Booking Calendar Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar Contact Form: from n/a through… |
| CVE-2016-10909 | Crítica (9.8) | 1.8% | — | 21 ago 2019 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. |
| CVE-2016-10908 | Media (6.1) | 0.91% | — | 21 ago 2019 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS. |