Netweblogic

Events Manager

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 18.12.2025 07:20:45
  • Zuletzt bearbeitet 18.12.2025 15:07:42

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input san...

  • EPSS 0.02%
  • Veröffentlicht 12.12.2025 11:15:51
  • Zuletzt bearbeitet 12.12.2025 15:17:31

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' ...

  • EPSS 0.06%
  • Veröffentlicht 12.12.2025 11:15:50
  • Zuletzt bearbeitet 12.12.2025 15:17:31

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can...

  • EPSS 0.12%
  • Veröffentlicht 09.07.2025 22:22:47
  • Zuletzt bearbeitet 11.07.2025 17:27:10

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization an...

  • EPSS 0.05%
  • Veröffentlicht 09.07.2025 22:22:47
  • Zuletzt bearbeitet 11.07.2025 17:26:52

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output e...

  • EPSS 32.53%
  • Veröffentlicht 09.07.2025 22:22:46
  • Zuletzt bearbeitet 11.07.2025 17:27:31

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied param...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 13.05.2014 14:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index....