Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Eventin HIGH 8.8
CVE-2025-4796

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due…

Fix: 4.0.35+
Fix from $1,950 2025-08-08
Eventin MEDIUM 6.1
CVE-2025-49321

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Refl…

Fix: 4.0.29+
Fix from $1,600 2025-06-27
Eventin CRITICAL 9.8
CVE-2025-47539EPSS 33%

Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a …

Fix: 4.0.27+
Fix from $2,300 2025-05-23
Eventin CRITICAL 9.8
CVE-2025-47445EPSS 5%

Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.…

Fix: 4.0.27+
Fix from $2,300 2025-05-14
Eventin HIGH 7.5
CVE-2025-3419

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to,…

Fix: 4.0.27+
Fix from $1,950 2025-05-08
Eventin HIGH 7.5
CVE-2025-39584

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-s…

Fix: 4.0.26+
Fix from $1,950 2025-04-16
Eventin HIGH 8.8
CVE-2025-1770

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to…

Fix: 4.0.25+
Fix from $1,950 2025-03-20
Eventin MEDIUM 5.3
CVE-2025-1766

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a…

Fix: 4.0.25+
Fix from $1,600 2025-03-20
Eventin HIGH 8.8
CVE-2025-26964

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-s…

Fix: 4.0.21+
Fix from $1,950 2025-02-25
Eventin HIGH 8.8
CVE-2024-56213

Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <…

Fix: 4.0.9+
Fix from $1,950 2024-12-31
Eventin HIGH 8.8
CVE-2023-49756

Missing Authorization vulnerability in Arraytics Eventin wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Fix: 3.3.53+
Fix from $1,950 2024-12-09
Wpcafe CRITICAL 9.8
CVE-2023-47805

Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Fix: 2.2.23+
Fix from $2,300 2024-12-09
Eventin HIGH 8.8
CVE-2024-7149

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to…

Fix: 4.0.9+
Fix from $1,950 2024-09-27
Wpcafe HIGH 8.8
CVE-2024-43135

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.Th…

Fix: 2.2.29+
Fix from $1,950 2024-08-13
Eventin MEDIUM 5.4
CVE-2024-37507

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.Th…

Fix: 4.0.0+
Fix from $1,600 2024-07-21
Wpcafe HIGH 8.8
CVE-2024-37513

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue a…

Fix: 2.2.28+
Fix from $1,950 2024-07-09
Wpcafe HIGH 8.8
CVE-2024-5431

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclu…

Fix: 2.2.26+
Fix from $1,950 2024-06-25
Wpcafe MEDIUM 5.4
CVE-2024-5427

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Sit…

Fix: 2.2.26+
Fix from $1,600 2024-05-31
Wpcafe MEDIUM 5.3
CVE-2024-1855

The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-S…

Fix: 2.2.24+
Fix from $1,600 2024-05-23
Eventin MEDIUM 5.3
CVE-2024-1122

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to…

Fix: 3.3.51+
Fix from $1,600 2024-02-09