Pixelite
Pixelite Events Manager: vulnerabilidades y CVE
Pixelite Events Manager tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-6976 | Media (5.4) | 0.25% | — | 9 jul 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient… |
| CVE-2025-6975 | Media (6.1) | 0.28% | — | 9 jul 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to… |
| CVE-2025-6970 | Alta (7.5) | 67% | — | 9 jul 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient… |
| CVE-2024-11260 | Alta (7.5) | 0.60% | — | 21 feb 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient… |
| CVE-2024-5889 | Media (6.1) | 0.31% | — | 29 jun 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to… |
| CVE-2024-3492 | Media (5.4) | 0.29% | — | 12 jun 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to,… |
| CVE-2024-30515 | Alta (8.8) | 0.32% | — | 9 jun 2024 | Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4. |
| CVE-2024-30421 | Media (4.3) | 0.21% | — | 28 mar 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1. |
| CVE-2024-2111 | Media (5.4) | 0.34% | — | 28 mar 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to… |
| CVE-2024-2110 | Media (4.3) | 0.21% | — | 28 mar 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce… |
| CVE-2024-0614 | Media (4.8) | 0.68% | — | 13 mar 2024 | The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This… |
| CVE-2023-48326 | Media (6.1) | 0.40% | — | 30 nov 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5. |
| CVE-2020-35037 | Media (6.1) | 0.91% | — | 1 dic 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues |
| CVE-2020-35012 | Alta (7.2) | 1.5% | — | 1 dic 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection |
| CVE-2019-16523 | Media (5.4) | 1.2% | — | 16 oct 2019 | The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and… |
| CVE-2013-7480 | Media (6.1) | 0.91% | — | 22 ago 2019 | The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. |
| CVE-2013-7479 | Media (6.1) | 0.91% | — | 22 ago 2019 | The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. |
| CVE-2013-7478 | Media (6.1) | 0.91% | — | 22 ago 2019 | The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. |
| CVE-2013-7477 | Media (6.1) | 0.91% | — | 22 ago 2019 | The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. |
| CVE-2012-6716 | Media (6.1) | 0.91% | — | 22 ago 2019 | The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links. |
| CVE-2015-9300 | Media (6.1) | 0.92% | — | 13 ago 2019 | The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues. |
| CVE-2015-9299 | Media (6.1) | 0.92% | — | 13 ago 2019 | The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS. |
| CVE-2015-9298 | Crítica (9.8) | 2.1% | — | 13 ago 2019 | The events-manager plugin before 5.6 for WordPress has code injection. |
| CVE-2015-9297 | Media (6.1) | 0.92% | — | 13 ago 2019 | The events-manager plugin before 5.6 for WordPress has XSS. |
| CVE-2018-13137 | Media (4.8) | 1.2% | — | 12 abr 2019 | The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI. |
| CVE-2018-0576 | Media (5.4) | 1.5% | — | 14 may 2018 | Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2018-9020 | Media (5.4) | 1.0% | — | 26 mar 2018 | The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.