Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

The Events Calendar MEDIUM 5.4
CVE-2025-5144

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and…

Fix: 6.13.2.1+
Fix from $1,600 2025-06-11
The Events Calendar MEDIUM 5.3
CVE-2024-5333

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access informatio…

Fix: 6.8.2.1+
Fix from $1,600 2024-12-16
The Events Calendar MEDIUM 6.1
CVE-2024-6931EPSS 16%

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6…

Fix: 6.6.4+
Fix from $1,600 2024-09-27
The Events Calendar CRITICAL 9.8
CVE-2024-8275EPSS 50%

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all v…

Fix: 6.6.4.1+
Fix from $2,300 2024-09-25
The Events Calendar CRITICAL 9.1
CVE-2024-4180

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

Fix: 6.4.0.1+
Fix from $2,300 2024-06-04
The Events Calendar MEDIUM 5.3
CVE-2023-6557

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the ro…

Fix: after 6.2.8.2
Fix from $1,600 2024-02-05
The Events Calendar HIGH 7.5
CVE-2023-6203

The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request

Fix: 6.2.8.1+
Fix from $1,950 2023-12-18
The Events Calendar MEDIUM 6.1
CVE-2019-15109

The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

Fix: 4.8.2+
Fix from $1,600 2019-08-21