cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcp-multi-view-calendar cp-multi-view-calendar

Direction: descending
Mar 29, 2026

Calendar Event Multi View # CVE-2026-25465

CVE, Research URL

CVE-2026-25465

Date
Mar 25, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Stored XSS.This issue affects CP Multi View Event Calendar : from n/a through <= 1.4.35.
Affected versions
max 1.4.35.
Status
vulnerable
Oct 11, 2025

Calendar Event Multi View # CVE-2025-58009

CVE, Research URL

CVE-2025-58009

Date
Sep 23, 2025
Research Description
Missing Authorization vulnerability in codepeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CP Multi View Event Calendar : from n/a through 1.4.32.
Affected versions
max 1.4.32.
Status
vulnerable
Jun 10, 2024

Calendar Event Multi View # CVE-2023-23814

CVE, Research URL

CVE-2023-23814

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13.
Affected versions
max 1.4.15.
Status
vulnerable
Jun 06, 2024

Calendar Event Multi View # CVE-2021-24498

CVE, Research URL

CVE-2021-24498

Date
Aug 02, 2021
Research Description
The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.
Affected versions
max 1.4.01.
Status
vulnerable

Calendar Event Multi View # CVE-2014-8586

CVE, Research URL

CVE-2014-8586

Date
Nov 04, 2014
Research Description
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
Affected versions
max 1.1.5.
Status
vulnerable

Calendar Event Multi View # CVE-2022-2846

CVE, Research URL

CVE-2022-2846

Date
Aug 17, 2022
Research Description
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.
Affected versions
max 1.4.15.
Status
vulnerable

Calendar Event Multi View # CVE-2023-28492

CVE, Research URL

CVE-2023-28492

Date
Jun 04, 2024
Research Description
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.
Affected versions
max 1.4.07.
Status
vulnerable