Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Eventon MEDIUM 5.4
CVE-2025-3527

The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings…

Fix: after 4.9.6
Fix from $1,600 2025-05-17
Eventon MEDIUM 5.9
CVE-2024-4752

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to…

Fix: 2.2.15+
Fix from $1,600 2024-07-13
Eventon MEDIUM 6.1
CVE-2023-7200

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cros…

Fix: 4.4.1+
Fix from $1,600 2024-01-29
Rsvp Events MEDIUM 6.1
CVE-2023-7170

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Refle…

Fix: 2.9.5+
Fix from $1,600 2024-01-22
Eventon MEDIUM 6.1
CVE-2024-0233

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 6.1
CVE-2024-0238

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not en…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 5.3
CVE-2024-0235EPSS 38%

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticate…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 5.3
CVE-2024-0236

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticate…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 5.3
CVE-2024-0237

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenti…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 6.5
CVE-2023-6158

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to…

Fix: after 4.5.4
Fix from $1,600 2024-01-10
Eventon Lite MEDIUM 6.1
CVE-2023-4635

The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due …

Fix: after 2.2.2
Fix from $1,600 2023-10-21
Eventon MEDIUM 5.3
CVE-2023-3219EPSS 8%

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, all…

Fix: 2.1.2+
Fix from $1,600 2023-07-10
Eventon MEDIUM 5.3
CVE-2023-2796EPSS 43%

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated vi…

Fix: 2.1.2+
Fix from $1,600 2023-07-10
Eventon MEDIUM 6.1
CVE-2020-29395EPSS 12%

The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

Fix: after 3.0.5
Fix from $1,600 2020-11-30