Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Eventprime
(Metagauss)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 12 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-06-20 | CVE-2023-35884 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions. | Eventprime | 6.1 | ||
2023-10-25 | CVE-2023-45637 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions. | Eventprime | 6.1 | ||
2023-10-31 | CVE-2023-4250 | The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | Eventprime | 6.1 | ||
2023-10-31 | CVE-2023-4251 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | Eventprime | 4.3 | ||
2023-10-31 | CVE-2023-5238 | The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website. | Eventprime | 6.1 | ||
2023-10-31 | CVE-2023-5519 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | Eventprime | 4.3 | ||
2023-11-27 | CVE-2023-4252 | The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment. | Eventprime | 5.3 | ||
2024-01-22 | CVE-2023-6447 | The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name. | Eventprime | 5.3 | ||
2024-06-09 | CVE-2024-31275 | Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4. | Eventprime | 9.8 | ||
2024-09-10 | CVE-2024-8369 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or password-protected events. | Eventprime | 5.3 |