VYPR

VikAppointments Services Booking Calendar

by WordPress

CVEs (2)

  • CVE-2026-15918HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper…

  • CVE-2025-22719HigJan 21, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikAppointments Services Booking Calendar vikappointments allows Stored XSS.This issue affects VikAppointments Services Booking Calendar: from n/a through <= 1.2.16.