Browse all 4 CVE security advisories affecting EventON. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-10033 | EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action — EventON Action UserCWE-862 | 7.3 | High | 2026-07-24 |
| CVE-2026-9711 | EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter — EventON (Pro) - WordPress Virtual Event Calendar PluginCWE-89 | 9.8 | Critical | 2026-06-30 |
| CVE-2025-3527 | EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — EventON (Pro) - WordPress Virtual Event Calendar PluginCWE-862 | 6.4 | Medium | 2025-05-17 |
| CVE-2023-6243 | EventON PRO - WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email — EventON (Pro) - WordPress Virtual Event Calendar PluginCWE-352 | 4.3 | Medium | 2024-10-19 |
This page lists every published CVE security advisory associated with EventON. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.