Myeventon maintains a focused portfolio of event-management and RSVP applications that face the web directly, presenting a narrowly scoped but publicly exposed attack surface. The vendor's vulnerability footprint concentrates in application-layer input handling and access control, with recurring weakness classes including cross-site scripting, missing authorization, cross-site request forgery, and authorization bypass that are endemic to web form processing and session management in event-facing platforms. Public exploit code has frequently emerged for vulnerabilities in this product line, reflecting the relative simplicity of web application flaws and the visibility of the applications themselves. Defenders deploying these applications should treat input sanitization, authentication logic, and CSRF protections as hardening priorities and maintain current patch levels. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myeventon over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2796MEDIUM The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and pa | Jul 10, 2023 | 5.3 | 61 | NO | YES |
CVE-2020-29395MEDIUM The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. | Nov 30, 2020 | 6.1 | 45 | NO | YES |
CVE-2024-0235MEDIUM The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addre | Jan 16, 2024 | 5.3 | 42 | NO | YES |
CVE-2023-3219MEDIUM The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors | Jul 10, 2023 | 5.3 | 40 | NO | YES |
CVE-2023-7200MEDIUM The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be | Jan 29, 2024 | 6.1 | 20 | NO | NO |
CVE-2023-6158MEDIUM The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on | Jan 10, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-7170MEDIUM The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which | Jan 22, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-4635MEDIUM The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitizat | Oct 21, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-0238MEDIUM The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be update | Jan 16, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-0233MEDIUM The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Re | Jan 16, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myeventon.
Media articles that mention a CVE ID that affects a product developed by Myeventon — matched by CVE ID, not by vendor name.