Mage-people
Mage-people Event Manager AND Tickets Selling FOR Woocommerce: vulnerabilidades y CVE
Mage-people Event Manager AND Tickets Selling FOR Woocommerce tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-5568 | Media (5.4) | 0.26% | — | 7 jun 2025 | The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes… |
| CVE-2024-43138 | Alta (8.8) | 0.63% | — | 13 ago 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for… |
| CVE-2024-24796 | Alta (8.8) | 0.50% | — | 12 feb 2024 | Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for… |
| CVE-2023-36383 | Media (5.4) | 0.33% | — | 18 jul 2023 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions. |
| CVE-2023-28422 | Media (4.8) | 0.37% | — | 23 mar 2023 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions. |
| CVE-2023-0144 | Media (5.4) | 0.48% | — | 6 feb 2023 | The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the… |
| CVE-2022-0478 | Alta (8.8) | 1.5% | — | 14 mar 2022 | The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which… |