Theeventscalendar

The Events Calendar

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.85%
  • Veröffentlicht 16.09.2025 05:25:26
  • Zuletzt bearbeitet 16.09.2025 12:49:16

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protecte...

  • EPSS 0.09%
  • Veröffentlicht 12.09.2025 01:46:00
  • Zuletzt bearbeitet 15.09.2025 15:22:38

The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...

  • EPSS 0.06%
  • Veröffentlicht 11.06.2025 12:22:52
  • Zuletzt bearbeitet 10.07.2025 00:25:36

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible...

  • EPSS 0.07%
  • Veröffentlicht 19.05.2025 14:44:54
  • Zuletzt bearbeitet 21.05.2025 20:25:33

Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Events Calendar: from n/a through 6.11.2.1.

  • EPSS 0.05%
  • Veröffentlicht 27.01.2025 15:15:13
  • Zuletzt bearbeitet 27.01.2025 15:15:13

Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery. This issue affects The Events Calendar: from n/a through 6.7.0.

  • EPSS 0.19%
  • Veröffentlicht 23.01.2025 12:15:26
  • Zuletzt bearbeitet 31.01.2025 16:12:19

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output ...

  • EPSS 0.17%
  • Veröffentlicht 02.01.2025 12:15:21
  • Zuletzt bearbeitet 02.01.2025 12:15:21

Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through 6.5.1.4.

  • EPSS 0.2%
  • Veröffentlicht 13.12.2024 15:15:16
  • Zuletzt bearbeitet 13.12.2024 15:15:16

Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2.

  • EPSS 0.18%
  • Veröffentlicht 15.04.2024 10:15:10
  • Zuletzt bearbeitet 21.11.2024 09:13:31

Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar.This issue affects The Events Calendar: from n/a through 6.3.0.