Web Calendar System versions 3.12 and 3.30 suffer from cross site scripting and remote SQL injection vulnerabilities.