Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-5144 The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and… The Events Calendar 6.13.2.1+ Fix from $1,6002025-06-11 MEDIUM 5.3 CVE-2024-5333 The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access informatio… The Events Calendar 6.8.2.1+ Fix from $1,6002024-12-16 MEDIUM 6.1 CVE-2024-6931EPSS 16% The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6… The Events Calendar 6.6.4+ Fix from $1,6002024-09-27 CRITICAL 9.8 CVE-2024-8275EPSS 50% The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all v… The Events Calendar 6.6.4.1+ Fix from $2,3002024-09-25 CRITICAL 9.1 CVE-2024-4180 The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. The Events Calendar 6.4.0.1+ Fix from $2,3002024-06-04 MEDIUM 5.3 CVE-2023-6557 The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the ro… The Events Calendar after 6.2.8.2 Fix from $1,6002024-02-05 HIGH 7.5 CVE-2023-6203 The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request The Events Calendar 6.2.8.1+ Fix from $1,9502023-12-18 MEDIUM 6.1 CVE-2019-15109 The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. The Events Calendar 4.8.2+ Fix from $1,6002019-08-21