Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Events Manager – Calendar, Bookings, Tickets, and more! — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Events Manager – Calendar, Bookings, Tickets, and more!, with AI-generated Chinese analysis, references, and POCs.

Vendor: netweblogic

CVE IDTitleCVSSSeverityPublished
CVE-2025-12976 Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode CWE-79 6.4 Medium2025-12-18
CVE-2025-12408 Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure CWE-200 5.3 Medium2025-12-12
CVE-2025-12407 Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion CWE-352 4.3 Medium2025-12-12
CVE-2025-6976 Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes CWE-79 6.4 Medium2025-07-09
CVE-2025-6975 Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter CWE-79 6.1 Medium2025-07-09
CVE-2025-6970 Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter CWE-89 7.5 High2025-07-09
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter CWE-89 7.5 High2025-02-21
CVE-2024-5889 Events Manager <= 6.4.8 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2024-06-29
CVE-2024-3492 Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes CWE-79 6.4 Medium2024-06-12
CVE-2024-2110 Events Manager <= 6.4.7.1 - Cross-Site Request Forgery CWE-352 4.3 Medium2024-03-28
CVE-2024-2111 Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-28
CVE-2024-0614 Events Manager <= 6.4.6.4 - Authenticated(Administator+) Stored Cross-Site Scripting via settings CWE-79 4.4 Medium2024-03-13

All 12 known CVE vulnerabilities affecting Events Manager – Calendar, Bookings, Tickets, and more! with full Chinese analysis, references, and POCs where available.