plugin

Spider Calendar Vulnerabilities

8 known security issues reported for the Spider Calendar WordPress plugin. Most recent disclosed May 15, 2015.

1 high

Running Spider Calendar on your site? Check whether your installed version is affected.

Scan your site free

Spider Calendar [spider-calendar] < 1.1.1 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in "many_sp_calendar". Update the plugin.

Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
May 15, 2015

Spider Calendar [spider-calendar] < 1.0.2 (closed)

unknown

Spider Calendar plugin is prone to multiple vulnerabilities such as cross-site scripting, SQL injection and HTTP parameter pollution. Update the plugin.

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Oct 3, 2012

Spider Calendar < 1.1.3 - Multiple Vulnerabilities

high

The Spider Calendar plugin for WordPress is vulnerable to generic SQL Injection, Cross-Site Scripting, and Parameter Pollution via several parameters in versions up to, and including,1.1.2 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This mak...

CVSS:
7.2
Affected:
up to 1.1.3
Fixed in:
1.1.3
Disclosed:
Oct 2, 2012

Spider Calendar [spider-calendar] < 1.1.3

unknown

The Spider Calendar plugin for WordPress is vulnerable to generic SQL Injection, Cross-Site Scripting, and Parameter Pollution via several parameters in versions up to, and including,1.1.2 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This mak...

Affected:
up to 1.1.3
Fixed in:
1.1.3
Disclosed:
Oct 2, 2012

Spider Calendar [spider-calendar] < 1.1.3 (closed)

unknown

The spider-calendar WordPress plugin was affected by a spidercalendarbig_seemore.php calendar_id Parameter SQL Injection security vulnerability.

Affected:
up to 1.1.3
Fixed in:
1.1.3

Spider Calendar [spider-calendar] < 1.1.1 (closed)

unknown

The spider-calendar WordPress plugin was affected by a &quot;many_sp_calendar&quot; Cross-Site Scripting security vulnerability.

Affected:
up to 1.1.1
Fixed in:
1.1.1

Spider Calendar [spider-calendar] <= 1.3.0 (unfixed + closed)

unknown

The spider-calendar WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.

Affected:
up to 1.3.0
Fix:
No patched version reported

Spider Calendar [spider-calendar] < 1.1.3 (closed)

unknown

The spider-calendar WordPress plugin was affected by a front_end/spidercalendarbig.php date Parameter XSS security vulnerability.

Affected:
up to 1.1.3
Fixed in:
1.1.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database