Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Events Manager – Calendar, Bookings, Tickets, and more! — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Events Manager – Calendar, Bookings, Tickets, and more!, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting the Events Manager – Calendar, Bookings, Tickets, and more! plugin, which functions as a critical scheduling and ticketing extension for WordPress sites. The collection encompasses a diverse range of security flaws, including Cross-Site Scripting, SQL Injection, and Unauthorized Access issues, documented over a period spanning from 2019 to the present day. By examining this dataset, researchers and administrators can track the vendor's advisory patterns, understand the prevalence of specific weakness classes like improper input validation, and review the comprehensive vulnerability history of this widely used product to assess its long-term security posture. This resource provides a structured view of past exploits and remediation trends, enabling informed risk management decisions for organizations relying on this software for event coordination and revenue generation.

Vendor: netweblogic

CVE ID Title CVSS Severity Published
CVE-2025-14945 Events Manager - Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes CWE-79 5.4 Medium 2026-09-05
CVE-2026-17089 Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter CWE-79 6.1 Medium 2026-08-25
CVE-2026-14280 Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys CWE-98 6.6 Medium 2026-08-25
CVE-2026-10627 Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters CWE-862 5.3 Medium 2026-08-25
CVE-2026-15023 Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action CWE-89 6.5 Medium 2026-08-25
CVE-2025-12976 Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode CWE-79 6.4 Medium 2025-12-18
CVE-2025-12407 Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion CWE-352 4.3 Medium 2025-12-12
CVE-2025-12408 Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure CWE-200 5.3 Medium 2025-12-12
CVE-2025-6976 Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes CWE-79 6.4 Medium 2025-07-09
CVE-2025-6970 Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter CWE-89 7.5 High 2025-07-09
CVE-2025-6975 Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter CWE-79 6.1 Medium 2025-07-09
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter CWE-89 7.5 High 2025-02-21
CVE-2024-5889 Events Manager <= 6.4.8 - Reflected Cross-Site Scripting CWE-79 6.1 Medium 2024-06-29
CVE-2024-3492 Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes CWE-79 6.4 Medium 2024-06-12
CVE-2024-2110 Events Manager <= 6.4.7.1 - Cross-Site Request Forgery CWE-352 4.3 Medium 2024-03-28
CVE-2024-2111 Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-03-28
CVE-2024-0614 Events Manager <= 6.4.6.4 - Authenticated(Administator+) Stored Cross-Site Scripting via settings CWE-79 4.4 Medium 2024-03-13

All 17 known CVE vulnerabilities affecting Events Manager – Calendar, Bookings, Tickets, and more! with full Chinese analysis, references, and POCs where available.