Booking calendar, Appointment Booking System

Booking calendar, Appointment Booking System has 23 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2026; 18 are fixed and 5 remain unpatched as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 8 high. 2023 was the busiest year with 6 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (30%). Other recurring categories include SQL Injection, Missing Authorization.

18 of the records (78%) have a vendor fix, while 5 remain unpatched. The oldest unresolved one dates back to 2026.

15 independent researchers contributed these findings, most of them (4) reported by d4wner.

01234567891011.01.2018Today11.01.20185.5Booking calendar, Appointment Booking System <= 2.1.7 - Cross-Site Scripting CVSS 5.5 · 11.01.20185.5Booking calendar, Appointment Booking System <= 2.1.7 - Cross-Site Scripting CVSS 5.5 · 11.01.20185.5Booking calendar, Appointment Booking System <= 2.1.7 - Cross-Site Scripting CVSS 5.5 · 11.01.201812.01.20188.8Booking calendar, Appointment Booking System <= 2.1.7 - Cross-Site Request Forgery CVSS 8.8 · 12.01.201807.06.20187.5Booking calendar, Appointment Booking System < 2.2.3 - Unauthenticated Parameter Manipulation CVSS 7.5 · 07.06.201821.11.20229.8Booking calendar, Appointment Booking System <= 3.2.1 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 21.11.202227.01.20234.3Booking calendar, Appointment Booking System <= 3.2.3 - Cross-Site Request Forgery CVSS 4.3 · 27.01.20235.5Booking calendar, Appointment Booking System <= 3.2.3 - Authenticated (Editor+) Stored Cross-Site Scripting CVSS 5.5 · 27.01.20235.3Booking calendar, Appointment Booking System <= 3.2.3 - Unauthenticated Bypass Vulnerability CVSS 5.3 · 27.01.202319.04.20237.2Booking calendar, Appointment Booking System <= 3.2.6 - Authenticated (Administrator+) SQL Injection via *_selected CVSS 7.2 · 19.04.202312.09.20237.2Booking calendar, Appointment Booking System <= 3.2.8 - Multiple Authenticated(Editor+) SQL Injection CVSS 7.2 · 12.09.202329.10.20237.2Booking Calendar WpDevArt <= 3.2.11 - Authenticated (Admin+) SQL Injection CVSS 7.2 · 29.10.202327.01.20244.1Booking calendar, Appointment Booking System <= 3.2.3 - Missing Authorization CVSS 4.1 · 27.01.202425.11.20247.2Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload CVSS 7.2 · 25.11.202423.12.20246.5Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 23.12.202406.01.20256.1Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id' CVSS 6.1 · 06.01.202501.07.20255.9Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id' CVSS 5.9 · 01.07.202515.12.20255.3Booking calendar, Appointment Booking System <= 3.2.30 - Missing Authorization CVSS 5.3 · 15.12.202518.03.20267.2Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 18.03.202602.07.20265.3Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization CVSS 5.3 · 02.07.202614.08.20265.3Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action CVSS 5.3 · 14.08.202617.08.20267.2Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 17.08.202618.08.20265.3Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 18.08.2026

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage78%
Open

5

Fixed

18

Get automatic notifications for all Booking calendar, Appointment Booking System vulnerabilities before they are exploited.

Most severe open issueCVSS 7.2CVE-2026-14334

Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

23 records
2026-08-18 00:00CVE-2026-73395
5.3
Medium
Jakub HermanNo
2026-08-17 00:00CVE-2026-14334
7.2
High
Samdup ChoephelNo
2026-08-14 14:05CVE-2026-8840
5.3
Medium
Raihan Adi ArbaNo
2026-07-02 00:00CVE-2026-57778
5.3
Medium
Nabil IrawanNo
2026-03-18 00:00CVE-2026-25435
7.2
High
dragonzenNo
2025-12-15 00:00CVE-2025-67574
5.3
Medium
Legion HunterYes
2025-07-01 14:49CVE-2026-15289
5.9
Medium
shaman0x01Yes
2025-01-06 00:00CVE-2024-12077
6.1
Medium
vgo0Yes
2024-12-23 21:34CVE-2024-10856
6.5
Medium
Peter ThaleikisYes
2024-11-25 00:00CVE-2024-9504
7.2
High
Rein Daelman (trein)Yes
Showing 1–10 of 23 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C