Booking calendar contact form
This hub aggregates every CVE we track for Booking calendar contact form, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM7HIGH3CRITICAL1
Monthly trend
0
0
1
1
0
0
0
0
0
1
0
0
0
1
0
0
0
0
1
0
3
0
0
0
2024-102026-09
Latest CVEs
The 11 most recently published vulnerabilities affecting Booking calendar contact form.
- CVE-2016-20068WordPress Booking Calendar Contact Form 1.0.23 SQL Injection8.2
- CVE-2016-20070WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS6.4
- CVE-2016-20069WordPress Booking Calendar Contact Form 1.0.23 SQL Injection8.2
- CVE-2026-6810Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover5.3
- CVE-2025-13318Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter5.3
- CVE-2025-48231WordPress Booking Calendar Contact Form plugin <= 1.2.58 - Cross Site Scripting (XSS) Vulnerability6.5
- CVE-2025-24723WordPress Booking Calendar Contact Form Plugin <= 1.2.55 - Stored Cross Site Scripting (XSS) vulnerability5.9
- CVE-2023-25037WordPress Booking Calendar Contact Form plugin <= 1.2.34 - Broken Access Control vulnerability4.3
- CVE-2023-36384WordPress Booking Calendar Contact Form Plugin <= 1.2.40 is vulnerable to Cross Site Scripting (XSS)7.1
- CVE-2016-10909The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.9.8
- CVE-2016-10908The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.6.1
Product normalization is registry-driven with AI assist and human review. How it works