Extension WordPress
Vulnérabilités SpiderCalendar
Cette page rassemble les failles publiées pour SpiderCalendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de SpiderCalendar
4 fiches
SpiderCalendar <= 1.6.64 – Reflected Cross-Site Scripting
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site…
*-1.5.65
1.6.65
13/01/2022
SpiderCalendar <= 1.5.51 – SQL Injection
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.
*-1.5.51
1.5.52
10/04/2017
SpiderCalendar <= 1.4.13 – Cross-Site Request Forgery
The SpiderCalendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.13. This is due to missing or incorrect nonce validation on the Manage_Spider_Calendar() function. This makes it possible for unauthenticated attackers…
*-1.4.13
1.4.14
11/03/2015
SpiderCalendar <= 1.4.9 – Unauthenticated SQL Injection
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.
[*, 1.4.10)
1.4.10
13/02/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.