Tickera develops a ticket and event management platform with a modest vulnerability footprint that concentrates on access-control and input-handling issues. The recurring weakness classes—cross-site scripting, missing and incorrect authorization, and code injection—reflect the web-application nature of the product and its handling of user-supplied event and ticketing data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tickera over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-35729HIGH Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tic | Jun 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-10263HIGH The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the softwa | Nov 5, 2024 | 7.3 | 23 | NO | NO |
CVE-2025-67939MEDIUM Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tic | Jan 22, 2026 | 6.5 | 22 | NO | NO |
CVE-2021-24797MEDIUM The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could | Dec 27, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-41861MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions. | Sep 27, 2023 | 6.1 | 20 | NO | NO |
CVE-2025-69355MEDIUM Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tic | Jan 6, 2026 | 4.3 | 18 | NO | NO |
CVE-2023-7252MEDIUM The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets. | Apr 22, 2024 | 5.3 | 18 | NO | NO |
CVE-2025-58611MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Tickera Tickera tickera-event-ticketing-system allows Cross Site Request Forgery.This issue affects Tickera: from n/a through <= | Sep 3, 2025 | 4.3 | 17 | NO | NO |
CVE-2022-4549MEDIUM The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CS | Jan 16, 2023 | 4.3 | 17 | NO | NO |
CVE-2025-30851MEDIUM Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tic | Mar 27, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tickera.
Media articles that mention a CVE ID that affects a product developed by Tickera — matched by CVE ID, not by vendor name.