Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webnus

First CVE: Feb 28, 2020Active for: 6 yearsTotal CVEs: 18
40.2
VTI Score
Medium

Webnus develops calendar and events management plugins for WordPress that are widely embedded in small-business and community websites, placing them in a prominent but specialized niche of the vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across its Modern Events Calendar product line through application-layer weakness classes including cross-site scripting, SQL injection, unrestricted file uploads, and access-control flaws that are characteristic of web-facing WordPress extensions. Defenders should treat Webnus plugin updates as a patching priority for sites where event management is deployed; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webnus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2020
6 years ago
Most Recent CVE
Jul 12, 2025
377 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24946CRITICAL
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX ac
Dec 13, 20219.889NOYES
CVE-2021-24145HIGH
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by adm
Mar 18, 20217.289NOYES
CVE-2021-24146HIGH
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthentic
Mar 18, 20217.561NOYES
CVE-2022-0364MEDIUM
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as cont
Mar 21, 20225.456NONO
CVE-2021-4458CRITICAL
The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions up to,
Jul 12, 20259.831NONO
CVE-2024-6522CRITICAL
The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This
Aug 7, 20249.629NONO
CVE-2024-5441HIGH
The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to
Jul 9, 20248.828NONO
CVE-2021-24149HIGH
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when
Mar 18, 20218.827NONO
CVE-2021-25046MEDIUM
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the
Jan 17, 20225.421NONO
CVE-2021-24925MEDIUM
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to bot
Dec 13, 20216.120NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
61%
22%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (38.9%)
Unknown0 (0.0%)
Required11 (61.1%)
Privileges Required
Low9 (50.0%)
High5 (27.8%)
None4 (22.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
11.1% of CVEs· 98th percentile
Nuclei
3 CVEs
16.7% of CVEs· 97th percentile
ExploitDB
3 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webnus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webnus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webnus's Products

View all 5 CNAs →

Top CWEs