Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-6976
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short…
Events Manager
6.6.5 / 7.0.4+
HIGH 7.5
CVE-2025-6970EPSS 61%
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ paramete…
Events Manager
6.6.5 / 7.0.4+
MEDIUM 6.1
CVE-2025-6975
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_he…
Events Manager
6.6.5 / 7.0.4+
HIGH 7.5
CVE-2024-11260
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status para…
Events Manager
6.6.4+
MEDIUM 6.1
CVE-2024-5889
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ pa…
Events Manager
6.4.9+
MEDIUM 5.4
CVE-2024-3492
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event…
Events Manager
6.4.8+
HIGH 8.8
CVE-2024-30515
Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.
Events Manager
6.4.7+
MEDIUM 5.4
CVE-2024-2111
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical locati…
Events Manager
6.4.7.2+
MEDIUM 6.1
CVE-2023-48326
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.Th…
Events Manager
after 6.4.5
MEDIUM 5.3
CVE-2022-3891
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user …
Wp Fullcalendar
1.5+
HIGH 7.2
CVE-2020-35012
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injec…
Events Manager
5.9.8+
MEDIUM 6.1
CVE-2020-35037
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead …
Events Manager
5.9.8+
MEDIUM 5.4
CVE-2019-16523
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of dat…
Events Manager
after 5.9.5
MEDIUM 6.1
CVE-2012-6716
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
Events Manager
5.1.7+
MEDIUM 6.1
CVE-2013-7477
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
Events Manager
5.5.2+
MEDIUM 6.1
CVE-2013-7478
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
Events Manager
5.5+
MEDIUM 6.1
CVE-2013-7479
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
Events Manager
5.3.9+
MEDIUM 6.1
CVE-2013-7480
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
Events Manager
5.3.6.1+
MEDIUM 6.1
CVE-2015-9299
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
Events Manager
5.5.7.1+
MEDIUM 6.1
CVE-2015-9300
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
Events Manager
5.5.7+
CRITICAL 9.8
CVE-2015-9298
The events-manager plugin before 5.6 for WordPress has code injection.
Events Manager
5.6+
MEDIUM 6.1
CVE-2015-9297
The events-manager plugin before 5.6 for WordPress has XSS.
Events Manager
5.6+
MEDIUM 5.4
CVE-2018-0576
Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script…
Events Manager
5.9+
MEDIUM 5.4
CVE-2018-9020
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
Events Manager
5.8.1.2+