Modern Events Calendar Lite

Modern Events Calendar Lite has 20 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; all 20 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 6 high. 2021 was the busiest year with 9 disclosures.

The most common weakness is Cross-Site Scripting, behind 11 of the records (55%). Other recurring categories include SQL Injection, Unrestricted Upload Of File With Dangerous Type.

Every one of the 20 issues recorded for Modern Events Calendar Lite has a vendor fix available, so running the current release closes all known holes.

12 independent researchers contributed these findings, most of them (4) reported by Nguyen Van Khanh.

01234567891027.02.2020Today27.02.20205.4Modern Events Calendar Lite <= 5.1.6 - Missing Authorization to Stored Cross-Site Scripting and Settings Update CVSS 5.4 · 27.02.202029.01.20217.2Modern Events Calendar Lite <= 5.16.4 - Authenticated Arbitrary File Upload leading to Remote Code Execution CVSS 7.2 · 29.01.20218.8Modern Events Calendar Lite <= 5.16.5 - Authenticated SQL Injection CVSS 8.8 · 29.01.20216.4Modern Events Calendar Lite <= 5.16.4 - Authenticated Stored Cross-Site Scripting CVSS 6.4 · 29.01.20217.5Modern Events Calendar Lite <= 5.16.4 - Unauthenticated Events Export CVSS 7.5 · 29.01.202106.09.20214.8Modern Events Calendar Lite < 5.22.1 - Admin+ Stored Cross-Site Scripting CVSS 4.8 · 06.09.202129.09.20215.4Modern Events Calendar Lite <= 5.22.2 - Authenticated Stored Cross Site Scripting CVSS 5.4 · 29.09.202115.11.20219.8Modern Events Calendar Lite <= 6.1.4 - Unauthenticated Blind SQL Injection via time Parameter CVSS 9.8 · 15.11.20216.1Modern Events Calendar Lite <= 6.1.0 - Reflected Cross-Site Scripting via current_month_divider parameter CVSS 6.1 · 15.11.202103.12.20215.4Modern Events Calendar Lite <= 6.1.6 - Subscriber+ Category Add Leading to Stored Cross-Site Scripting CVSS 5.4 · 03.12.202128.02.20226.4Modern Events Calendar Lite <= 6.3.0 - Stored Cross-Site Scripting CVSS 6.4 · 28.02.202214.04.20225.5Modern Events Calendar Lite <= 6.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 5.5 · 14.04.202201.06.20226.4Modern Events Calendar Lite <= 6.2.9 - Authenticated (Contributor+) Cross-Site Scripting CVSS 6.4 · 01.06.202214.03.20234.4Modern Events Calendar lite < 6.10.5 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 14.03.202328.09.20234.4Modern Events Calendar lite < 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.09.202308.07.20248.8Modern Events Calendar <= 7.11.0 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 08.07.202406.08.20248.5Modern Events Calendar <= 7.12.1 - Authenticated (Subscriber+) Server Side Request Forgery CVSS 8.5 · 06.08.202405.06.20255.3Modern Events Calendar <= 7.21.9 - Information Exposure CVSS 5.3 · 05.06.202511.07.20255.9Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection CVSS 5.9 · 11.07.202529.06.20267.5Modern Events Calendar (Lite & Pro) <= 7.33.0 - Unauthenticated SQL Injection CVSS 7.5 · 29.06.2026

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

20

Get automatic notifications for all Modern Events Calendar Lite vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2021-24946

Modern Events Calendar Lite <= 6.1.4 - Unauthenticated Blind SQL Injection via time Parameter

Read the full analysis

Vulnerability Records

20 records
2026-06-29 00:00CVE-2026-11349
7.5
High
Anthony CihanYes
2025-07-11 00:00CVE-2021-4458
5.9
Medium
AnonymousYes
2025-06-05 15:05CVE-2025-5733
5.3
Medium
Abdullah ShittuYes
2024-08-06 21:57CVE-2024-6522
8.5
High
FoxyyyYes
2024-07-08 00:00CVE-2024-5441
8.8
High
FoxyyyYes
2023-09-28 00:00CVE-2023-4021
4.4
Medium
Marco WotschkaYes
2023-03-14 00:00CVE-2023-1400
4.4
Medium
Pavak TiwariYes
2022-06-01 00:00CVE-2022-30533
6.4
Medium
Tsutomu AramakiYes
2022-04-14 00:00CVE-2022-27848
5.5
Medium
Muhammad DaffaYes
2022-02-28 00:00CVE-2022-0364
6.4
Medium
Rohan ChaudhariYes
Showing 1–10 of 20 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C