k5n CVE Vulnerabilities & Metrics

Focus on k5n vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About k5n Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with k5n. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total k5n CVEs: 1
Earliest CVE date: 16 Mar 2007, 21:19 UTC
Latest CVE date: 15 Nov 2024, 11:15 UTC

Latest CVE reference: CVE-2024-1097

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical k5n CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.27

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 5
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS k5n CVEs

These are the five CVEs with the highest CVSS scores for k5n, sorted by severity first and recency.

All CVEs for k5n

CVE-2024-1097 k5n vulnerability CVSS: 0 15 Nov 2024, 11:15 UTC

A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading to the theft of user accounts and cookies.

CVE-2012-0846 k5n vulnerability CVSS: 4.3 08 Oct 2012, 20:55 UTC

Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable.

CVE-2011-3814 k5n vulnerability CVSS: 5.0 24 Sep 2011, 00:55 UTC

WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files.

CVE-2010-0638 k5n vulnerability CVSS: 6.8 15 Feb 2010, 18:30 UTC

Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2010-0637 k5n vulnerability CVSS: 6.8 12 Feb 2010, 22:30 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administrators for requests that (1) delete an event or (2) ban an IP address from posting via unknown vectors. NOTE: some of these details are obtained from third party information.

CVE-2010-0636 k5n vulnerability CVSS: 4.3 12 Feb 2010, 22:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.

CVE-2008-2836 k5n vulnerability CVSS: 7.5 24 Jun 2008, 19:41 UTC

PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a 0 value for the noSet parameter, a different vector than CVE-2007-1483.

CVE-2007-1483 k5n vulnerability CVSS: 7.5 16 Mar 2007, 21:19 UTC

Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.