E-dynamics
E-dynamics Events Made Easy: vulnerabilidades y CVE
E-dynamics Events Made Easy tiene 10 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28162 | Alta (7.1) | 0.25% | — | 24 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. |
| CVE-2026-75963 | Alta (7.5) | 0.87% | — | 20 ago 2026 | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated… |
| CVE-2026-14842 | Media (5.3) | 0.30% | — | 6 ago 2026 | The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a… |
| CVE-2026-14843 | Media (5.3) | 0.30% | — | 31 jul 2026 | The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with… |
| CVE-2026-59557 | Media (6.5) | 0.33% | — | 27 jul 2026 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. |
| CVE-2023-28660 | Alta (8.8) | 0.87% | — | 22 mar 2023 | The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action. |
| CVE-2023-0404 | Media (5.4) | 0.51% | — | 19 ene 2023 | The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it… |
| CVE-2022-1905 | Crítica (9.8) | 37% | — | 20 jun 2022 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection |
| CVE-2021-25030 | Alta (8.8) | 1.4% | — | 3 ene 2022 | The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As… |
| CVE-2021-24813 | Media (4.8) | 0.70% | — | 1 nov 2021 | The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.