CVE-2023-47609: OSS-Calendar OSS Calendar

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute arbitrary code or obtain and/or alter the information stored in the database by sending a specially crafted request.

Affected products

Published 2023-11-14. Last modified 2026-06-17.