Vulnerabilities
Summary — last 7 days
New vulnerabilities2,680▼ 660 vs. last week
Critical / high1,277▼ 279 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
12 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.32% | — | Simple Google Calendar Outlook Events WidgetAI | 8/4/2026 | 8/26/2026 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request. | |
| Deferred | Medium (4.4) | 0.22% | — | List View Google CalendarAI | 4/15/2026 | 6/17/2026 | The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event description in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Deferred | Medium (5.3) | 0.29% | — | Google CalendarAIGoogle Calendar EventsAI | 12/30/2025 | 10/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Calendar Events: from n/a through <= 3.5.9. | |
| Deferred | Medium (5.3) | 0.27% | — | Pretty Google CalendarAI | 12/20/2025 | 9/30/2026 | The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to retrieve the Google API key set in the plugin's… | |
| Deferred | Medium (4.3) | 0.22% | — | Michielvaneerd Private Google CalendarsAI | 11/11/2025 | 10/7/2026 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the… | |
| Deferred | High (8.5) | 0.57% | — | Eurocizia WP Google Calendar ManagerAI | 3/26/2025 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EuroCizia WP Google Calendar Manager wp-gcalendar allows Blind SQL Injection.This issue affects WP Google Calendar Manager: from n/a through <= 2.1. | |
| Deferred | Medium (6.5) | 0.32% | — | Lbell Pretty Google CalendarAI | 4/29/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Google Calendar allows Stored XSS.This issue affects Pretty Google Calendar: from n/a through 1.7.2. | |
| Modified | Medium (5.4) | 0.74% | 💥 PoC | Dandulaney Dan's Embedder FOR Google Calendar | 2/5/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2. | |
| Modified | Medium (5.4) | 0.31% | — | Michielvaneerd Private Google Calendars | 1/8/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125. | |
| Modified | High (8.8) | 0.21% | — | Mattmckenny Stout Google Calendar | 10/16/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions. | |
| Modified | Medium (6.5) | 1.0% | — | Jenkins Google Calendar | 9/25/2019 | 6/17/2026 | Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modified | Medium (4.3) | 2.4% | — | Google Calendar Events Project Google Calendar Events | 10/16/2014 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php. |