Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Events Manager MEDIUM 5.4
CVE-2025-6976

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short…

Fix: 6.6.5 / 7.0.4+
Fix from $1,600 2025-07-09
Events Manager HIGH 7.5
CVE-2025-6970EPSS 61%

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ paramete…

Fix: 6.6.5 / 7.0.4+
Fix from $1,950 2025-07-09
Events Manager MEDIUM 6.1
CVE-2025-6975

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_he…

Fix: 6.6.5 / 7.0.4+
Fix from $1,600 2025-07-09
Events Manager HIGH 7.5
CVE-2024-11260

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status para…

Fix: 6.6.4+
Fix from $1,950 2025-02-21
Events Manager MEDIUM 6.1
CVE-2024-5889

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ pa…

Fix: 6.4.9+
Fix from $1,600 2024-06-29
Events Manager MEDIUM 5.4
CVE-2024-3492

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event…

Fix: 6.4.8+
Fix from $1,600 2024-06-12
Events Manager HIGH 8.8
CVE-2024-30515

Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.

Fix: 6.4.7+
Fix from $1,950 2024-06-09
Events Manager MEDIUM 5.4
CVE-2024-2111

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical locati…

Fix: 6.4.7.2+
Fix from $1,600 2024-03-28
Events Manager MEDIUM 6.1
CVE-2023-48326

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.Th…

Fix: after 6.4.5
Fix from $1,600 2023-11-30
Wp Fullcalendar MEDIUM 5.3
CVE-2022-3891

The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user …

Fix: 1.5+
Fix from $1,600 2023-02-13
Events Manager HIGH 7.2
CVE-2020-35012

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injec…

Fix: 5.9.8+
Fix from $1,950 2021-12-01
Events Manager MEDIUM 6.1
CVE-2020-35037

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead …

Fix: 5.9.8+
Fix from $1,600 2021-12-01
Events Manager MEDIUM 5.4
CVE-2019-16523

The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of dat…

Fix: after 5.9.5
Fix from $1,600 2019-10-16
Events Manager MEDIUM 6.1
CVE-2012-6716

The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.

Fix: 5.1.7+
Fix from $1,600 2019-08-22
Events Manager MEDIUM 6.1
CVE-2013-7477

The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.

Fix: 5.5.2+
Fix from $1,600 2019-08-22
Events Manager MEDIUM 6.1
CVE-2013-7478

The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.

Fix: 5.5+
Fix from $1,600 2019-08-22
Events Manager MEDIUM 6.1
CVE-2013-7479

The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.

Fix: 5.3.9+
Fix from $1,600 2019-08-22
Events Manager MEDIUM 6.1
CVE-2013-7480

The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.

Fix: 5.3.6.1+
Fix from $1,600 2019-08-22
Events Manager MEDIUM 6.1
CVE-2015-9299

The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.

Fix: 5.5.7.1+
Fix from $1,600 2019-08-13
Events Manager MEDIUM 6.1
CVE-2015-9300

The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.

Fix: 5.5.7+
Fix from $1,600 2019-08-13
Events Manager CRITICAL 9.8
CVE-2015-9298

The events-manager plugin before 5.6 for WordPress has code injection.

Fix: 5.6+
Fix from $2,300 2019-08-13
Events Manager MEDIUM 6.1
CVE-2015-9297

The events-manager plugin before 5.6 for WordPress has XSS.

Fix: 5.6+
Fix from $1,600 2019-08-13
Events Manager MEDIUM 5.4
CVE-2018-0576

Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script…

Fix: 5.9+
Fix from $1,600 2018-05-14
Events Manager MEDIUM 5.4
CVE-2018-9020

The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

Fix: 5.8.1.2+
Fix from $1,600 2018-03-26