Eventon
Vendor:
First CVE: Nov 30, 2020 · Active for 5 years
18
Total CVEs
More Total CVEs than 94% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 13% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Eventon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2020
5 years ago
Most Recent CVE
May 17, 2025
437 days ago
CVE Severity & Scoring
Eventon18 CVEs
100%
All CVEs353,173 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (33.3%)
Unknown0 (0.0%)
Required12 (66.7%)
Privileges Required
Low1 (5.6%)
High5 (27.8%)
None12 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2796MEDIUM The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and pa | Jul 10, 2023 | 5.3 | 61 | NO | YES |
CVE-2020-29395MEDIUM The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. | Nov 30, 2020 | 6.1 | 45 | NO | YES |
CVE-2024-0235MEDIUM The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addre | Jan 16, 2024 | 5.3 | 42 | NO | YES |
CVE-2023-3219MEDIUM The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors | Jul 10, 2023 | 5.3 | 40 | NO | YES |
CVE-2023-7200MEDIUM The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be | Jan 29, 2024 | 6.1 | 20 | NO | NO |
CVE-2023-6158MEDIUM The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on | Jan 10, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-0238MEDIUM The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be update | Jan 16, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-0233MEDIUM The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Re | Jan 16, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-3527MEDIUM The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versi | May 17, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-6910MEDIUM The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting a | Sep 9, 2024 | 4.8 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
3 CVEs
16.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Eventon
Top CWEs
Versions
No cataloged versions.