Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-4458 The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX… Modern Events Calendar Lite 6.4.0+ Fix from $2,3002025-07-12 CRITICAL 9.6 CVE-2024-6522 The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'me… Modern Events Calendar 7.13.0+ Fix from $2,3002024-08-07 HIGH 8.8 CVE-2024-5441 The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image… Modern Events Calendar Lite 7.12.0+ Fix from $1,9502024-07-09 MEDIUM 5.4 CVE-2022-30533 Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitr… Modern Events Calendar Lite 6.3.0+ Fix from $1,6002022-06-16 MEDIUM 5.4 CVE-2022-0364EPSS 70% The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow u… Modern Events Calendar Lite 6.4.0+ Fix from $1,6002022-03-21 MEDIUM 5.4 CVE-2021-25046 The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters … Modern Events Calendar Lite 6.2.0+ Fix from $1,6002022-01-17 CRITICAL 9.8 CVE-2021-24946EPSS 73% The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in t… Modern Events Calendar Lite 6.1.5+ Fix from $2,3002021-12-13 MEDIUM 6.1 CVE-2021-24925 The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_m… Modern Events Calendar Lite 6.1.5+ Fix from $1,6002021-12-13 MEDIUM 5.4 CVE-2021-24716 The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust setting… Modern Events Calendar Lite 5.22.3+ Fix from $1,6002021-11-01 HIGH 8.8 CVE-2021-24149 Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in th… Modern Events Calendar Lite 5.16.6+ Fix from $1,9502021-03-18 HIGH 7.5 CVE-2021-24146EPSS 31% Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp… Modern Events Calendar Lite 5.16.5+ Fix from $1,9502021-03-18 HIGH 7.2 CVE-2021-24145EPSS 88% Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing… Modern Events Calendar Lite 5.16.5+ Fix from $1,9502021-03-18 MEDIUM 5.4 CVE-2021-24147 Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_c… Modern Events Calendar Lite 5.16.5+ Fix from $1,6002021-03-18 MEDIUM 5.4 CVE-2020-9459 Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote… Modern Events Calendar Lite after 5.1.6 Fix from $1,6002020-02-28