Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-29395 1 Myeventon 1 Eventon 2024-11-21 6.1 Medium
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
CVE-2024-6910 2 Eventon Wordpress Plugin, Myeventon 2 Eventon Wordpress Plugin, Eventon 2024-10-07 4.8 Medium
The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.