« Volver al listado

Pixelite

Pixelite Events Manager: vulnerabilidades y CVE

Pixelite Events Manager tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE27
Últimos 12 meses0
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-6976Media (5.4)0.25%—9 jul 2025
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient…
CVE-2025-6975Media (6.1)0.28%—9 jul 2025
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to…
CVE-2025-6970Alta (7.5)67%—9 jul 2025
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient…
CVE-2024-11260Alta (7.5)0.60%—21 feb 2025
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient…
CVE-2024-5889Media (6.1)0.31%—29 jun 2024
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to…
CVE-2024-3492Media (5.4)0.29%—12 jun 2024
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to,…
CVE-2024-30515Alta (8.8)0.32%—9 jun 2024
Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.
CVE-2024-30421Media (4.3)0.21%—28 mar 2024
Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.
CVE-2024-2111Media (5.4)0.34%—28 mar 2024
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to…
CVE-2024-2110Media (4.3)0.21%—28 mar 2024
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce…
CVE-2024-0614Media (4.8)0.68%—13 mar 2024
The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This…
CVE-2023-48326Media (6.1)0.40%—30 nov 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
CVE-2020-35037Media (6.1)0.91%—1 dic 2021
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
CVE-2020-35012Alta (7.2)1.5%—1 dic 2021
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
CVE-2019-16523Media (5.4)1.2%—16 oct 2019
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and…
CVE-2013-7480Media (6.1)0.91%—22 ago 2019
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
CVE-2013-7479Media (6.1)0.91%—22 ago 2019
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
CVE-2013-7478Media (6.1)0.91%—22 ago 2019
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
CVE-2013-7477Media (6.1)0.91%—22 ago 2019
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
CVE-2012-6716Media (6.1)0.91%—22 ago 2019
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
CVE-2015-9300Media (6.1)0.92%—13 ago 2019
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
CVE-2015-9299Media (6.1)0.92%—13 ago 2019
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
CVE-2015-9298Crítica (9.8)2.1%—13 ago 2019
The events-manager plugin before 5.6 for WordPress has code injection.
CVE-2015-9297Media (6.1)0.92%—13 ago 2019
The events-manager plugin before 5.6 for WordPress has XSS.
CVE-2018-13137Media (4.8)1.2%—12 abr 2019
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
CVE-2018-0576Media (5.4)1.5%—14 may 2018
Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-9020Media (5.4)1.0%—26 mar 2018
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System2
  2. T1190 Exploit Public-Facing Application2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Pixelite