Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Myeventon

First CVE: Nov 30, 2020Active for: 6 yearsTotal CVEs: 21
27.8
VTI Score
Low

Myeventon maintains a focused portfolio of event-management and RSVP applications that face the web directly, presenting a narrowly scoped but publicly exposed attack surface. The vendor's vulnerability footprint concentrates in application-layer input handling and access control, with recurring weakness classes including cross-site scripting, missing authorization, cross-site request forgery, and authorization bypass that are endemic to web form processing and session management in event-facing platforms. Public exploit code has frequently emerged for vulnerabilities in this product line, reflecting the relative simplicity of web application flaws and the visibility of the applications themselves. Defenders deploying these applications should treat input sanitization, authentication logic, and CSRF protections as hardening priorities and maintain current patch levels. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Myeventon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2020
5 years ago
Most Recent CVE
May 17, 2025
433 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2796MEDIUM
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and pa
Jul 10, 20235.361NOYES
CVE-2020-29395MEDIUM
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
Nov 30, 20206.145NOYES
CVE-2024-0235MEDIUM
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addre
Jan 16, 20245.342NOYES
CVE-2023-3219MEDIUM
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors
Jul 10, 20235.340NOYES
CVE-2023-7200MEDIUM
The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be
Jan 29, 20246.120NONO
CVE-2023-6158MEDIUM
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on
Jan 10, 20246.520NONO
CVE-2023-7170MEDIUM
The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which
Jan 22, 20246.119NONO
CVE-2023-4635MEDIUM
The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitizat
Oct 21, 20236.119NONO
CVE-2024-0238MEDIUM
The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be update
Jan 16, 20246.118NONO
CVE-2024-0233MEDIUM
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Re
Jan 16, 20246.118NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (28.6%)
Unknown0 (0.0%)
Required15 (71.4%)
Privileges Required
Low1 (4.8%)
High5 (23.8%)
None15 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
19.0% of CVEs· 97th percentile
ExploitDB
3 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Myeventon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Myeventon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Myeventon's Products

View all 3 CNAs →

Top CWEs