E Dynamics maintains a focused product line centered on event management and scheduling software. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E Dynamics over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1905CRITICAL The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthentic | Jun 20, 2022 | 9.8 | 43 | NO | NO |
CVE-2021-25030HIGH The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, av | Jan 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-28660HIGH The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list acti | Mar 22, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-0404MEDIUM The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, an | Jan 19, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-24813MEDIUM The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when | Nov 1, 2021 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E Dynamics.
Media articles that mention a CVE ID that affects a product developed by E Dynamics — matched by CVE ID, not by vendor name.