Extension WordPress
Vulnérabilités Timely All-in-One Events Calendar
Cette page rassemble les failles publiées pour Timely All-in-One Events Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Timely All-in-One Events Calendar
4 fiches
Timely All-in-One Events Calendar <= 2.5.38 – Cross-Site Scripting
The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters related to event input in versions up to, and including, 2.5.38 due to insufficient input sanitization and output escaping. This makes it…
*-2.5.38
2.5.39
04/05/2019
Timely All-in-One Events Calendar < 1.10 – Cross-Site Scripting
The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…
[*, 1.10)
1.10
14/11/2013
All-in-One Events Calendar < 1.10 – SQL Injection
The All-in-One Events Calendar plugin for WordPress is vulnerable to SQL Injection via the “ai1ec_cat_ids”, “ai1ec_post_ids” and “ai1ec_tag_ids” parameters in versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of…
[*, 1.10)
1.10
07/03/2013
Timely All-in-One Events Calendar < 1.6 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (3) title, (4)…
[*, 1.6)
1.6
11/04/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.