Description
** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.
Remediation
References
Related Vulnerabilities
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Multiple Vulnerabilities (4.1.2)
MySQL CVE-2020-14836 Vulnerability (CVE-2020-14836)
WordPress Plugin Royal Gallery 'upload.php' Arbitrary File Upload (2.1)
WordPress Plugin Appointment Booking Calendar Cross-Site Scripting (1.3.34)
Oracle JRE Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2026-22007)