Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Modern Events Calendar Lite — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Modern Events Calendar Lite, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for Modern Events Calendar Lite, a calendar plugin distributed by Modern Tribe. It collects security advisories and known weaknesses affecting this specific software component. The dataset covers vulnerabilities reported over the past several years, providing a historical context for the product's security posture. Readers can use this page to track the vendor's advisory history, understand common weakness classes such as cross-site scripting or privilege escalation, and review the product's vulnerability timeline. The aggregated view allows security teams to identify recurring issues, assess risk exposure, and correlate fixes with specific releases. No individual CVE identifiers are listed in this summary, but the underlying data supports detailed lookups. This resource serves as a centralized reference for developers and administrators maintaining deployments of Modern Events Calendar Lite, enabling them to verify patch statuses and monitor emerging threats.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2021-4458 Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection CWE-89 5.9 Medium 2025-07-12
CVE-2025-5733 Modern Events Calendar <= 7.21.9 - Information Exposure CWE-201 5.3 Medium 2025-06-06
CVE-2023-4021 Modern Events Calendar lite < 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting CWE-79 4.4 Medium 2023-10-20
CVE-2023-1400 Modern Events Calendar lite < 6.5.2 - Admin+ Stored XSS 4.8 - 2023-03-27
CVE-2022-30533 Modern Events Calendar Lite 跨站脚本漏洞 5.4 - 2022-06-16
CVE-2022-0364 Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scripting CWE-79 5.4 - 2022-03-21
CVE-2021-25046 Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSS CWE-79 5.4 - 2022-01-17
CVE-2021-24946 Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection CWE-89 9.8 - 2021-12-13
CVE-2021-24925 Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scripting CWE-79 6.1 - 2021-12-13
CVE-2021-24716 Modern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site Scripting CWE-79 5.4 - 2021-11-01
CVE-2021-24687 Modern Events Calendar Lite < 5.22.2 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 - 2021-10-04
CVE-2021-24145 Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE CWE-434 7.2 - 2021-03-18
CVE-2021-24146 Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export CWE-284 - - 2021-03-18
CVE-2021-24147 Modern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS) CWE-79 5.4 - 2021-03-18
CVE-2021-24149 Modern Events Calendar Lite < 5.16.6 - Authenticated SQL Injection CWE-89 8.8 - 2021-03-18

All 15 known CVE vulnerabilities affecting Modern Events Calendar Lite with full Chinese analysis, references, and POCs where available.