İçeriğe atla
Noroxi

The Events Calendar

the-events-calendar · eklenti

The Events Calendar için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

24 bilinen açık

5 kritik · 4 kayıt için istismar kodu yayımlanmış · son kayıt 30 Eyl 2026

Güvenlik açıkları

  • CVE-2026-78159

    The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation

    Kritik 9.8
  • CVE-2026-78006

    The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

    Kritik 9.8
  • CVE-2026-78265

    WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability

    Kritik 9.8
  • CVE-2024-8275

    The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection

    Kritik 9.8
  • CVE-2026-49772

    WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability

    Kritik 9.3
  • CVE-2026-3585

    The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import

    Yüksek 7.5
  • CVE-2025-12197

    The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s

    Yüksek 7.5
  • CVE-2025-9807

    The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection

    Yüksek 7.5
  • CVE-2024-6931

    The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting

    Orta 6.1
  • CVE-2019-15109

    The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

    Orta 6.1
  • CVE-2026-97285

    WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability

    Orta 5.4
  • CVE-2026-2694

    The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API

    Orta 5.4
  • CVE-2025-15043

    The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control

    Orta 5.4
  • CVE-2025-69352

    WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability

    Orta 5.4
  • CVE-2025-5144

    The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

    Orta 5.4
  • CVE-2025-48246

    WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability

    Orta 5.4
  • CVE-2025-24537

    WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerability

    Orta 5.4
  • CVE-2024-12118

    The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Orta 5.4
  • CVE-2025-12192

    The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure

    Orta 5.3
  • CVE-2023-35777

    WordPress The Events Calendar plugin <= 6.1.2.2 - Broken Access Control vulnerability

    Orta 5.3
  • CVE-2023-6557

    The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure

    Orta 5.3
  • CVE-2025-12175

    The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure

    Orta 4.3
  • CVE-2024-37518

    WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerability

    Orta 4.3
  • CVE-2024-31433

    WordPress The Events Calendar plugin <= 6.3.0 - Cross Site Request Forgery (CSRF) vulnerability

    Orta 4.3

← Dizine dön