Mobileeventsmanager is a narrowly scoped mobile event management platform whose vulnerability exposure centers on its primary product and clusters around application-layer input-handling flaws, notably CSV formula-injection and cross-site scripting weaknesses. These weakness classes reflect the product's web and data-handling surface where user input requires thorough sanitization and output encoding. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mobileeventsmanager over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1194HIGH The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions a | Sep 16, 2022 | 8.8 | 22 | NO | NO |
CVE-2021-25049MEDIUM The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks | Jan 24, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mobileeventsmanager.
Media articles that mention a CVE ID that affects a product developed by Mobileeventsmanager — matched by CVE ID, not by vendor name.