Webnus records
18 published records for vendor webnus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 11.1%
- Pre-auth RCE
- 0
- With a fix record
- 5.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-284 Improper Access Control1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2021-24946Weaponized | Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injectionwebnus · modern events calendar lite · CWE-89 | Critical9.8 | — | 72.8% | Dec 13, 2021 |
54Plan | CVE-2021-24145Weaponized | Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCEwebnus · modern events calendar lite · CWE-434 | High7.2 | — | 87.2% | Mar 18, 2021 |
42Plan | CVE-2022-0364No exploit | Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scriptingwebnus · modern events calendar lite · CWE-79 | Medium5.4 | — | 69.6% | Mar 21, 2022 |
39Monitor | CVE-2021-24146Proof of concept | Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Exportwebnus · modern events calendar lite · CWE-284 | High7.5 | — | 31.0% | Mar 18, 2021 |
39Monitor | CVE-2021-4458No exploit | Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injectionwebnus · modern events calendar lite · CWE-89 | Critical9.8 | — | 0.4% | Jul 12, 2025 |
38Monitor | CVE-2024-6522No exploit | Modern Events Calendar <= 7.12.1 - Authenticated (Subscriber+) Server Side Request Forgerywebnus · modern events calendar · CWE-918 | Critical9.6 | — | 0.4% | Aug 7, 2024 |
35Monitor | CVE-2021-24149No exploit | Modern Events Calendar Lite < 5.16.6 - Authenticated SQL Injectionwebnus · modern events calendar lite · CWE-89 | High8.8 | — | 1.5% | Mar 18, 2021 |
35Monitor | CVE-2024-5441No exploit | Modern Events Calendar <= 7.11.0 - Authenticated (Subscriber+) Arbitrary File Uploadwebnus · modern events calendar · CWE-434 | High8.8 | — | 1.1% | Jul 9, 2024 |
24Monitor | CVE-2021-24925No exploit | Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scriptingwebnus · modern events calendar lite · CWE-79 | Medium6.1 | — | 0.8% | Dec 13, 2021 |
21Monitor | CVE-2020-9459No exploit | Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allowebnus · modern events calendar lite · CWE-79 | Medium5.4 | — | 1.0% | Feb 28, 2020 |
21Monitor | CVE-2021-24147No exploit | Modern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS)webnus · modern events calendar lite · CWE-79 | Medium5.4 | — | 0.7% | Mar 18, 2021 |
21Monitor | CVE-2021-24716No exploit | Modern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site Scriptingwebnus · modern events calendar lite · CWE-79 | Medium5.4 | — | 0.7% | Nov 1, 2021 |
21Monitor | CVE-2021-25046No exploit | Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSSwebnus · modern events calendar lite · CWE-79 | Medium5.4 | — | 0.6% | Jan 17, 2022 |
21Monitor | CVE-2022-30533No exploit | Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject webnus · modern events calendar lite · CWE-79 | Medium5.4 | — | 0.6% | Jun 15, 2022 |
19Monitor | CVE-2021-24687No exploit | Modern Events Calendar Lite < 5.22.2 - Admin+ Stored Cross-Site Scriptingwebnus · modern events calendar lite · CWE-79 | Medium4.8 | — | 0.6% | Oct 4, 2021 |
19Monitor | CVE-2022-27848No exploit | WordPress Modern Events Calendar Lite plugin <= 6.5.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitywebnus · modern events calendar lite · CWE-79 | Medium4.8 | — | 0.6% | Apr 14, 2022 |
19Monitor | CVE-2023-1400No exploit | Modern Events Calendar lite < 6.5.2 - Admin+ Stored XSSwebnus · modern events calendar lite · CWE-79 | Medium4.8 | — | 0.5% | Mar 27, 2023 |
19Monitor | CVE-2023-4021No exploit | Modern Events Calendar lite < 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scriptingwebnus · modern events calendar lite · CWE-79 | Medium4.8 | — | 0.4% | Oct 20, 2023 |
- CVE-2021-2494661This week
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
CriticalCVSS 9.8WeaponizedEPSS 73%webnus · modern events calendar liteDec 13, 2021
- CVE-2021-2414554Plan
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
HighCVSS 7.2WeaponizedEPSS 87%webnus · modern events calendar liteMar 18, 2021
- CVE-2022-036442Plan
Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scripting
MediumCVSS 5.4No exploitEPSS 70%webnus · modern events calendar liteMar 21, 2022
- CVE-2021-2414639Monitor
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
HighCVSS 7.5Proof of conceptEPSS 31%webnus · modern events calendar liteMar 18, 2021
- CVE-2021-445839Monitor
Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection
CriticalCVSS 9.8No exploitEPSS 0%webnus · modern events calendar liteJul 12, 2025
- CVE-2024-652238Monitor
Modern Events Calendar <= 7.12.1 - Authenticated (Subscriber+) Server Side Request Forgery
CriticalCVSS 9.6No exploitEPSS 0%webnus · modern events calendarAug 7, 2024
- CVE-2021-2414935Monitor
Modern Events Calendar Lite < 5.16.6 - Authenticated SQL Injection
HighCVSS 8.8No exploitEPSS 2%webnus · modern events calendar liteMar 18, 2021
- CVE-2024-544135Monitor
Modern Events Calendar <= 7.11.0 - Authenticated (Subscriber+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%webnus · modern events calendarJul 9, 2024
- CVE-2021-2492524Monitor
Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%webnus · modern events calendar liteDec 13, 2021
- CVE-2020-945921Monitor
Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allo
MediumCVSS 5.4No exploitEPSS 1%webnus · modern events calendar liteFeb 28, 2020
- CVE-2021-2414721Monitor
Modern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 1%webnus · modern events calendar liteMar 18, 2021
- CVE-2021-2471621Monitor
Modern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site Scripting
MediumCVSS 5.4No exploitEPSS 1%webnus · modern events calendar liteNov 1, 2021
- CVE-2021-2504621Monitor
Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSS
MediumCVSS 5.4No exploitEPSS 1%webnus · modern events calendar liteJan 17, 2022
- CVE-2022-3053321Monitor
Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject
MediumCVSS 5.4No exploitEPSS 1%webnus · modern events calendar liteJun 15, 2022
- CVE-2021-2468719Monitor
Modern Events Calendar Lite < 5.22.2 - Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 1%webnus · modern events calendar liteOct 4, 2021
- CVE-2022-2784819Monitor
WordPress Modern Events Calendar Lite plugin <= 6.5.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 1%webnus · modern events calendar liteApr 14, 2022
- CVE-2023-140019Monitor
Modern Events Calendar lite < 6.5.2 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 1%webnus · modern events calendar liteMar 27, 2023
- CVE-2023-402119Monitor
Modern Events Calendar lite < 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 0%webnus · modern events calendar liteOct 20, 2023