CVE-2012-1495: Webcalendar Project Webcalendar

Critical severity, CVSS 9.8. EPSS: 79.8% chance of exploitation in the next 30 days.

install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.

Affected products

Published 2020-01-27. Last modified 2026-06-16.