Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-6976 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… Events Manager 6.6.5 / 7.0.4+ Fix from $1,6002025-07-09 HIGH 7.5 CVE-2025-6970EPSS 61% The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ paramete… Events Manager 6.6.5 / 7.0.4+ Fix from $1,9502025-07-09 MEDIUM 6.1 CVE-2025-6975 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_he… Events Manager 6.6.5 / 7.0.4+ Fix from $1,6002025-07-09 HIGH 7.5 CVE-2024-11260 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status para… Events Manager 6.6.4+ Fix from $1,9502025-02-21 MEDIUM 6.1 CVE-2024-5889 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ pa… Events Manager 6.4.9+ Fix from $1,6002024-06-29 MEDIUM 5.4 CVE-2024-3492 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event… Events Manager 6.4.8+ Fix from $1,6002024-06-12 HIGH 8.8 CVE-2024-30515 Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4. Events Manager 6.4.7+ Fix from $1,9502024-06-09 MEDIUM 5.4 CVE-2024-2111 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical locati… Events Manager 6.4.7.2+ Fix from $1,6002024-03-28 MEDIUM 6.1 CVE-2023-48326 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.Th… Events Manager after 6.4.5 Fix from $1,6002023-11-30 MEDIUM 5.3 CVE-2022-3891 The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user … Wp Fullcalendar 1.5+ Fix from $1,6002023-02-13 HIGH 7.2 CVE-2020-35012 The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injec… Events Manager 5.9.8+ Fix from $1,9502021-12-01 MEDIUM 6.1 CVE-2020-35037 The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead … Events Manager 5.9.8+ Fix from $1,6002021-12-01 MEDIUM 5.4 CVE-2019-16523 The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of dat… Events Manager after 5.9.5 Fix from $1,6002019-10-16 MEDIUM 6.1 CVE-2012-6716 The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links. Events Manager 5.1.7+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2013-7477 The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. Events Manager 5.5.2+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2013-7478 The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. Events Manager 5.5+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2013-7479 The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. Events Manager 5.3.9+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2013-7480 The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. Events Manager 5.3.6.1+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2015-9299 The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS. Events Manager 5.5.7.1+ Fix from $1,6002019-08-13 MEDIUM 6.1 CVE-2015-9300 The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues. Events Manager 5.5.7+ Fix from $1,6002019-08-13 CRITICAL 9.8 CVE-2015-9298 The events-manager plugin before 5.6 for WordPress has code injection. Events Manager 5.6+ Fix from $2,3002019-08-13 MEDIUM 6.1 CVE-2015-9297 The events-manager plugin before 5.6 for WordPress has XSS. Events Manager 5.6+ Fix from $1,6002019-08-13 MEDIUM 5.4 CVE-2018-0576 Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script… Events Manager 5.9+ Fix from $1,6002018-05-14 MEDIUM 5.4 CVE-2018-9020 The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature. Events Manager 5.8.1.2+ Fix from $1,6002018-03-26