Community Events Project
Community Events Project Community Events: vulnerabilidades y CVE
Community Events Project Community Events tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-6270 | Media (4.8) | 0.35% | — | 5 ago 2024 | The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2024-6271 | Media (5.4) | 0.26% | — | 22 jul 2024 | The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack |
| CVE-2022-44742 | Media (4.8) | 0.39% | — | 23 mar 2023 | Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions. |
| CVE-2021-24496 | Media (6.1) | 0.83% | — | 2 ago 2021 | The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected… |
| CVE-2015-3313 | Crítica (9.8) | 8.3% | — | 7 sept 2017 | SQL injection vulnerability in WordPress Community Events plugin before 1.4. |