Skip to content
Noroxi

Webnus records

18 published records for vendor webnus.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 11.1%
Pre-auth RCE
0
With a fix record
5.6%
Median publish → KEV
No record has entered KEV

All records

18 records
  • CVE-2021-24946
    61This week

    Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection

    CriticalCVSS 9.8WeaponizedEPSS 73%

    webnus · modern events calendar liteDec 13, 2021

  • Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE

    HighCVSS 7.2WeaponizedEPSS 87%

    webnus · modern events calendar liteMar 18, 2021

  • Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scripting

    MediumCVSS 5.4No exploitEPSS 70%

    webnus · modern events calendar liteMar 21, 2022

  • Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export

    HighCVSS 7.5Proof of conceptEPSS 31%

    webnus · modern events calendar liteMar 18, 2021

  • CVE-2021-4458
    39Monitor

    Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection

    CriticalCVSS 9.8No exploitEPSS 0%

    webnus · modern events calendar liteJul 12, 2025

  • CVE-2024-6522
    38Monitor

    Modern Events Calendar <= 7.12.1 - Authenticated (Subscriber+) Server Side Request Forgery

    CriticalCVSS 9.6No exploitEPSS 0%

    webnus · modern events calendarAug 7, 2024

  • Modern Events Calendar Lite < 5.16.6 - Authenticated SQL Injection

    HighCVSS 8.8No exploitEPSS 2%

    webnus · modern events calendar liteMar 18, 2021

  • CVE-2024-5441
    35Monitor

    Modern Events Calendar <= 7.11.0 - Authenticated (Subscriber+) Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 1%

    webnus · modern events calendarJul 9, 2024

  • Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    webnus · modern events calendar liteDec 13, 2021

  • CVE-2020-9459
    21Monitor

    Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allo

    MediumCVSS 5.4No exploitEPSS 1%

    webnus · modern events calendar liteFeb 28, 2020

  • Modern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 1%

    webnus · modern events calendar liteMar 18, 2021

  • Modern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    webnus · modern events calendar liteNov 1, 2021

  • Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    webnus · modern events calendar liteJan 17, 2022

  • Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject

    MediumCVSS 5.4No exploitEPSS 1%

    webnus · modern events calendar liteJun 15, 2022

  • Modern Events Calendar Lite < 5.22.2 - Admin+ Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 1%

    webnus · modern events calendar liteOct 4, 2021

  • WordPress Modern Events Calendar Lite plugin <= 6.5.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 1%

    webnus · modern events calendar liteApr 14, 2022

  • CVE-2023-1400
    19Monitor

    Modern Events Calendar lite < 6.5.2 - Admin+ Stored XSS

    MediumCVSS 4.8No exploitEPSS 1%

    webnus · modern events calendar liteMar 27, 2023

  • CVE-2023-4021
    19Monitor

    Modern Events Calendar lite < 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 0%

    webnus · modern events calendar liteOct 20, 2023