Extension WordPress

Vulnérabilités Events Manager – Calendar, Bookings, Tickets, and more!, page 2

Cette page rassemble les failles publiées pour Events Manager – Calendar, Bookings, Tickets, and more!, leurs plages de versions affectées et les correctifs signalés dans la base locale.

35Vulnérabilités
1Critiques
35Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Events Manager – Calendar, Bookings, Tickets, and more!

35 fiches

CVE-2019-16523 Moyenne · 6,4
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 5.9.5 – Authenticated Stored Cross-Site Scripting

The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.

Versions affectées

*-5.9.5

Correctif

5.9.6

Publication

16/10/2019

CVE-2013-7477 Moyenne · 6,1
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 5.5.1 – Multiple Cross-Site Scripting

The Events Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-5.5.1

Correctif

5.5.2

Publication

01/08/2014

CVE-2013-1407 Moyenne · 6,1
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php;…

Versions affectées

[*, 5.3.5)

Correctif

5.3.5

Publication

01/08/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités