CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Community Events Project 1Community Events Jun 17, 2026 Aug 5, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfi...Show more |
1Community Events Project 1Community Events Jun 17, 2026 Jul 22, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack |
1Community Events Project 1Community Events Jun 17, 2026 Mar 23, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions. |
1Community Events Project 1Community Events Jun 17, 2026 Aug 2, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cros...Show more |
1Community Events Project 1Community Events May 13, 2026 Sep 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in WordPress Community Events plugin before 1.4. |