Extension WordPress
Vulnérabilités Events Manager – Calendar, Bookings, Tickets, and more!, page 2
Cette page rassemble les failles publiées pour Events Manager – Calendar, Bookings, Tickets, and more!, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Events Manager – Calendar, Bookings, Tickets, and more!
35 fiches
Events Manager <= 5.9.7.1 – CSV Injection
The Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.9.7.1 through the use of the Microsoft Excel DDE function. This allows low-privileged attackers to embed untrusted input into exported CSV…
*-5.9.7.1
5.9.7.2
05/02/2020
Events Manager <= 5.9.5 – Authenticated Stored Cross-Site Scripting
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.
*-5.9.5
5.9.6
16/10/2019
Events Manager <= 5.9.4 – Cross-Site Scripting
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
*-5.9.4
5.9.5
18/07/2018
Events Manager <= 5.8.1.3 – Stored Cross-Site Scripting
Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[*, 5.9)
5.9
27/04/2018
Events Manager <= 5.8.1.1 – Cross-Site Scripting
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
[*, 5.8.1.2)
5.8.1.2
26/03/2018
Events Manager <= 5.5.7.1 – Code Injection
The Events Manager plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 5.5.7.1. This makes it possible for attackers to inject code onto the server and potentially execute it.
[*, 5.6)
5.6
10/08/2015
Events Manager <= 5.5.7.1 – Cross-Site Scripting
The events-manager plugin before 5.6 for WordPress has XSS.
[*, 5.6)
5.6
10/08/2015
Events Manager < 5.5.7.1 – Cross-Site Scripting
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS via the dbem_event_reapproved_email_body parameter.
[*, 5.5.7.1)
5.5.7.1
04/06/2015
Events Manager < 5.5.7 – Cross-Site Scripting
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
[*, 5.5.7)
5.5.7
23/05/2015
Events Manager <= 5.5.1 – Multiple Cross-Site Scripting
The Events Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-5.5.1
5.5.2
01/08/2014
Events Manager < 5.3.9 – Cross-Site Scripting
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
[*, 5.3.9)
5.3.9
01/08/2014
Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php;…
[*, 5.3.5)
5.3.5
01/08/2014
Events Manager < 5.5 – Cross-Site Scripting
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
[*, 5.5)
5.5
14/08/2013
Events Manager <= 5.3.6 – Multiple Cross-Site Scripting
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
*-5.3.6
5.3.6.1
27/02/2013
Events Manager < 5.1.7 – Cross-Site Scripting
The Events Manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
[*, 5.1.7)
5.1.7
22/05/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.