Known Vulnerabilities for Events Manager by @msykes
Listed below are 10 of the newest known vulnerabilities associated with "Events Manager" by "@msykes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77990 json | Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-77989 json | Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCur... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-66457 json | Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-57713 json | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-34150 json | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, pr... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-18366 json | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access contr... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-18057 json | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a S... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-18050 json | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporar... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-17089 json | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scri... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-16064 json | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object... | Not Provided | 2026-08-02 | 2026-08-03 |