The Events Calendar
the-events-calendar · eklenti
The Events Calendar için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
24 bilinen açık
5 kritik · 4 kayıt için istismar kodu yayımlanmış · son kayıt 30 Eyl 2026
Güvenlik açıkları
- Kritik 9.8
The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation
- Kritik 9.8
The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution
- Kritik 9.8
WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability
- Kritik 9.8
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
- Kritik 9.3
WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability
- Yüksek 7.5
The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import
- Yüksek 7.5
The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s
- Yüksek 7.5
The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection
- Orta 6.1
The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting
- Orta 6.1
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
- Orta 5.4
WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability
- Orta 5.4
The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API
- Orta 5.4
The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control
- Orta 5.4
WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability
- Orta 5.4
The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
- Orta 5.4
WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability
- Orta 5.4
WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerability
- Orta 5.4
The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Orta 5.3
The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure
- Orta 5.3
WordPress The Events Calendar plugin <= 6.1.2.2 - Broken Access Control vulnerability
- Orta 5.3
The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
- Orta 4.3
The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure
- Orta 4.3
WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerability
- Orta 4.3
WordPress The Events Calendar plugin <= 6.3.0 - Cross Site Request Forgery (CSRF) vulnerability