joedolson records
4 published records for vendor joedolson.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2023-6360Proof of concept | The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' pajoedolson · my calendar · CWE-89 | Critical9.8 | — | 63.1% | Nov 30, 2023 |
21Monitor | CVE-2024-1274No exploit | My Calendar < 3.4.24 - Authenticated Stored XSSjoedolson · my calendar · CWE-79 | Medium5.4 | — | 0.4% | Apr 2, 2024 |
19Monitor | CVE-2023-34377No exploit | WordPress My Content Management Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)joedolson · my content management · CWE-79 | Medium4.8 | — | 0.4% | Aug 5, 2023 |
11Monitor | CVE-2012-6527No exploit | Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary wwordpress · wordpress · CWE-79 | Low2.6 | — | 2.2% | Jan 31, 2013 |
- CVE-2023-636058Plan
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' pa
CriticalCVSS 9.8Proof of conceptEPSS 63%joedolson · my calendarNov 30, 2023
- CVE-2024-127421Monitor
My Calendar < 3.4.24 - Authenticated Stored XSS
MediumCVSS 5.4No exploitEPSS 0%joedolson · my calendarApr 2, 2024
- CVE-2023-3437719Monitor
WordPress My Content Management Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%joedolson · my content managementAug 5, 2023
- CVE-2012-652711Monitor
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary w
LowCVSS 2.6No exploitEPSS 2%wordpress · wordpressJan 31, 2013