Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

arraytics — Vulnerabilities & Security Advisories 52

Browse all 52 CVE security advisories affecting arraytics. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Arraytics operates as a specialized provider of advanced threat detection and response solutions, primarily targeting industrial control systems and critical infrastructure environments. With thirty-eight Common Vulnerabilities and Exposures (CVEs) currently on record, the platform has historically exhibited significant security weaknesses, particularly in the areas of remote code execution and cross-site scripting. These flaws often stem from insufficient input validation and improper access controls, allowing attackers to escalate privileges or execute arbitrary commands within the managed network. While specific major public breaches remain limited in detailed reporting, the high volume of disclosed vulnerabilities indicates systemic issues in the software development lifecycle. The presence of these defects poses substantial risks to operational technology environments, where successful exploitation could lead to severe disruptions in industrial processes. Continuous patching and rigorous security audits are essential to mitigate these persistent exposure points.

CVE ID Title CVSS Severity Published
CVE-2025-3419 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) CWE-73 7.5 High 2025-05-08
CVE-2025-39452 WordPress WPCafe plugin <= 2.2.32 - Local File Inclusion vulnerability — WPCafe CWE-98 7.5 High 2025-04-17
CVE-2025-39584 WordPress Eventin plugin <= 4.0.25 - Local File Inclusion Vulnerability — Eventin CWE-98 7.5 High 2025-04-16
CVE-2025-30829 WordPress WPCafe plugin <= 2.2.31 - Local File Inclusion vulnerability — WPCafe CWE-98 7.5 High 2025-03-27
CVE-2025-30828 WordPress Timetics plugin <= 1.0.29 - Broken Access Control vulnerability — Timetics CWE-862 5.3 Medium 2025-03-27
CVE-2025-1770 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) CWE-22 8.8 High 2025-03-20
CVE-2025-1766 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) CWE-862 5.3 Medium 2025-03-20
CVE-2025-26964 WordPress Eventin plugin <= 4.0.20 - Local File Inclusion vulnerability — Eventin CWE-98 7.5 High 2025-02-25
CVE-2024-56213 WordPress Eventin plugin <= 4.0.7 - Contributor+ Limited Local File Inclusion vulnerability — Eventin CWE-35 6.5 Medium 2024-12-31
CVE-2024-11275 WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion — Timetics – Appointment Booking & Scheduling CWE-639 4.3 Medium 2024-12-13
CVE-2023-47805 WordPress WPCafe plugin <= 2.2.22 - Broken Access Control vulnerability — WPCafe CWE-862 5.3 Medium 2024-12-09
CVE-2023-49756 WordPress Eventin plugin <= 3.3.52 - Authenticated Notice Dismissal Vulnerability — Eventin CWE-862 5.4 Medium 2024-12-09
CVE-2024-37427 WordPress Timetics plugin <= 1.0.21 - Broken Access Control vulnerability — Timetics CWE-862 5.3 Medium 2024-11-01
CVE-2024-43923 WordPress Timetics plugin <= 1.0.23 - Broken Access Control vulnerability — Timetics CWE-862 5.3 Medium 2024-11-01
CVE-2024-9263 WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover — Timetics – Appointment Booking & Scheduling CWE-639 9.8 Critical 2024-10-17
CVE-2024-7149 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) CWE-22 8.8 High 2024-09-27
CVE-2024-6033 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) CWE-862 4.3 Medium 2024-07-17
CVE-2024-5431 WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode — WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System CWE-98 8.8 High 2024-06-25
CVE-2024-1094 Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation — Timetics – Appointment Booking & Scheduling CWE-862 7.3 High 2024-06-14
CVE-2024-5427 WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode — WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System CWE-79 6.4 Medium 2024-05-31
CVE-2024-1855 WPCafe <= 2.2.23 - Unauthenticated Blind Server-Side Request Forgery — WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System CWE-918 5.3 Medium 2024-05-23
CVE-2024-1122 Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) CWE-862 5.3 Medium 2024-02-09

This page lists every published CVE security advisory associated with arraytics. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.