Imithemes develops a modestly represented event-management product, Eventer, whose vulnerability profile skews toward serious outcomes with a meaningful share reaching critical severity. The recurring exposure centers on application-layer input-handling and access-control weaknesses, including SQL injection variants, cross-site scripting, path traversal, and missing authorization controls that are characteristic of web application platforms. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imithemes over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-39481CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer eventer allows Blind SQL Injection.This issue affects Evente | May 16, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-39482HIGH Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventer: from n/a throug | May 16, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-39483MEDIUM Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injection.This issue affects Eventer: from n/a through < 3.9.9.1. | Aug 14, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-11135HIGH The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees' function in all versions up to, and including, 3.9.8 due to | Jan 28, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-0959MEDIUM The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 du | Mar 7, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-22635MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Eventer eventer allows Reflected XSS.This issue affects Eventer: fro | Feb 23, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-10799MEDIUM The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it pos | Jan 17, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-11134MEDIUM The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, | Feb 3, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-11133MEDIUM The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, | Feb 3, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-11132MEDIUM The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9.4 due to insufficient input sanitization and ou | Feb 3, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imithemes.
Media articles that mention a CVE ID that affects a product developed by Imithemes — matched by CVE ID, not by vendor name.