The Community Events Project maintains a web-based events management application where disclosures center on application-layer input-handling and state-management issues, particularly cross-site scripting, cross-site request forgery, and SQL injection. Treat this as a compact, narrowly scoped vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Community Events Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-3313CRITICAL SQL injection vulnerability in WordPress Community Events plugin before 1.4. | Sep 7, 2017 | 9.8 | 44 | NO | YES |
CVE-2021-24496MEDIUM The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an | Aug 2, 2021 | 6.1 | 21 | NO | NO |
CVE-2022-44742MEDIUM Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions. | Mar 23, 2023 | 4.8 | 19 | NO | NO |
CVE-2024-6270MEDIUM The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-S | Aug 5, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-6271MEDIUM The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary even | Jul 22, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Community Events Project.
Media articles that mention a CVE ID that affects a product developed by Community Events Project — matched by CVE ID, not by vendor name.