Home/Product/pixelite events manager
Product

pixelite events manager

27 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-6976
< 6.6.5
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
6.4MEDIUM
CVE-2025-6975
< 6.6.5
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v
6.1MEDIUM
CVE-2025-6970
< 6.6.5
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the
7.5HIGH
CVE-2024-11260
< 6.6.4
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the
7.5HIGH
CVE-2024-5889
< 6.4.9
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v
6.1MEDIUM
CVE-2024-3492
< 6.4.8
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
6.4MEDIUM
CVE-2024-30515
< 6.4.7
Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.
4.3MEDIUM
CVE-2024-2111
< 6.4.7.2
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
6.4MEDIUM
CVE-2024-2110
< 6.4.7.2
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in al
4.3MEDIUM
CVE-2024-0614
< 6.4.7
The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and
4.4MEDIUM
CVE-2023-48326
<= 6.4.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allo
7.1HIGH
CVE-2020-35037
< 5.9.8
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages
6.1MEDIUM
CVE-2020-35012
< 5.9.8
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, lead
7.2HIGH
CVE-2019-16523
<= 5.9.5
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding a
5.4MEDIUM
CVE-2013-7480
< 5.3.6.1
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
6.1MEDIUM
CVE-2013-7479
< 5.3.9
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
6.1MEDIUM
CVE-2013-7478
< 5.5
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
6.1MEDIUM
CVE-2013-7477
< 5.5.2
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
6.1MEDIUM
CVE-2012-6716
< 5.1.7
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
6.1MEDIUM
CVE-2015-9300
< 5.5.7
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
6.1MEDIUM
CVE-2015-9299
< 5.5.7.1
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
6.1MEDIUM
CVE-2015-9298
< 5.6
The events-manager plugin before 5.6 for WordPress has code injection.
9.8CRITICAL
CVE-2015-9297
< 5.6
The events-manager plugin before 5.6 for WordPress has XSS.
6.1MEDIUM
CVE-2018-13137
all versions
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?
4.8MEDIUM
CVE-2018-0576
< 5.9
Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject a
5.4MEDIUM
CVE-2018-9020
< 5.8.1.2
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps
5.4MEDIUM
CVE-2013-1407
<= 5.3.4
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before