| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-28037 | WordPress EventON plugin <= 4.9.12 - Reflected Cross Site Scripting (XSS) vulnerability | ashanjay | EventON | 中危 | - | 2026-03-05 05:54:14 | Deep Dive |
| CVE-2025-63064 | WordPress EventON plugin <= 4.9.12 - Cross Site Scripting (XSS) vulnerability | ashanjay | EventON | - | - | 2025-12-09 14:52:34 | Deep Dive |
| CVE-2025-8091 | EventON Lite <= 2.4.7 - Authenticated (Contributor+) Information Disclosure | ashanjay | EventON – Events Calendar | Medium | 4.3 | 2025-08-15 08:25:39 | Deep Dive |
| CVE-2025-47565 | WordPress EventON plugin <= 4.9.9 - Broken Access Control vulnerability | ashanjay | EventON | Medium | 6.3 | 2025-07-04 11:18:05 | Deep Dive |
| CVE-2025-3527 | EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | EventON | EventON (Pro) - WordPress Virtual Event Calendar Plugin | Medium | 6.4 | 2025-05-17 11:17:16 | Deep Dive |
| CVE-2025-47564 | WordPress EventON plugin <= 4.9.8 - Broken Access Control vulnerability | ashanjay | EventON | Medium | 5.3 | 2025-05-16 15:45:19 | Deep Dive |
| CVE-2025-48116 | WordPress EventON plugin <= 2.4.4 - Broken Access Control Vulnerability | Ashan Perera | EventON | Medium | 5.3 | 2025-05-16 15:45:09 | Deep Dive |
| CVE-2025-47494 | WordPress EventON plugin <= 2.4.1 - Local File Inclusion Vulnerability | Ashan Perera | EventON | High | 7.5 | 2025-05-07 14:19:54 | Deep Dive |
| CVE-2025-32614 | WordPress EventON plugin <= 2.4 - Local File Inclusion vulnerability | Ashan Perera | EventON | High | 8.8 | 2025-04-11 08:43:00 | Deep Dive |
| CVE-2025-32160 | WordPress EventON plugin <= 2.4.1 - Local File Inclusion vulnerability | Ashan Perera | EventON | High | 7.5 | 2025-04-10 08:09:43 | Deep Dive |
| CVE-2023-6243 | EventON PRO - WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email | EventON | EventON (Pro) - WordPress Virtual Event Calendar Plugin | Medium | 4.3 | 2024-10-19 06:42:00 | Deep Dive |
| CVE-2024-6910 | EventON < 2.2.17 - Admin+ Stored XSS | Unknown | EventON | - | - | 2024-09-09 06:00:02 | Deep Dive |
| CVE-2024-4752 | EventON < 2.2.15 - Admin+ Stored Cross-Site Scripting via event subtitle | Unknown | EventON | - | - | 2024-07-13 06:00:07 | Deep Dive |
| CVE-2024-6180 | EventON <= 2.2.15 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates | ashanjay | EventON – Events Calendar | High | 7.2 | 2024-07-09 07:38:43 | Deep Dive |
| CVE-2024-33940 | WordPress EventON plugin <= 2.2.14 - Cross Site Scripting (XSS) vulnerability | Ashan Jay | EventON | Medium | 5.9 | 2024-05-03 07:00:14 | Deep Dive |
| CVE-2023-7200 | EventON < 4.4.1 - Reflected Cross-Site Scripting | Unknown | EventON | 中危 | - | 2024-01-29 14:44:27 | Deep Dive |
| CVE-2023-7170 | EventON-RSVP < 2.9.5 - Reflected XSS | Unknown | EventON-RSVP | 中危 | - | 2024-01-22 19:14:23 | Deep Dive |
| CVE-2024-0238 | EventON (Free < 2.2.8, Premium < 4.5.6) - Unauthenticated Arbitrary Post Metadata Update | Unknown | EventON Premium | 中危 | - | 2024-01-16 15:57:05 | Deep Dive |
| CVE-2024-0235 | EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure | Unknown | EventON | 中危 | - | 2024-01-16 15:57:04 | Deep Dive |
| CVE-2024-0233 | EventON (Free < 2.2.8, Premium < 4.5.5) - Reflected XSS | Unknown | EventON | 中危 | - | 2024-01-16 15:57:02 | Deep Dive |