Web Calendar System versions 3.40 and below suffer from cross site scripting and remote SQL injection vulnerabilities.