Known Vulnerabilities for Events Manager by @msykes
Listed below are 10 of the newest known vulnerabilities associated with "Events Manager" by "@msykes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66457 json | Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-57713 json | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-34150 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, pr... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-18366 json | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access contr... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-18057 json | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a S... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-18050 json | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporar... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-16064 json | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object... | Not Provided | 2026-08-02 | 2026-08-03 |
| CVE-2026-15148 json | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-14782 json | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Custo... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-14315 json | The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJ... | Not Provided | 2026-08-01 | 2026-08-03 |