The Events Calendar

Explore The Events Calendar vulnerabilities across all versions. Currently tracking 29 known vulnerabilities, including severity, impact, and patch status.

01234567891025.04.2016Today25.04.20164.7The Events Calendar < 4.1.1.1 - Open Redirect CVSS 4.7 · 25.04.201604.03.20196.1The Events Calendar <= 4.8.1 - Cross-Site Scripting via tribe_paged Parameter CVSS 6.1 · 04.03.201904.03.20226.3Freemius SDK <= 2.4.2 - Missing Authorization Checks CVSS 6.3 · 04.03.202218.07.20236.1Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get CVSS 6.1 · 18.07.202325.07.20234.3The Events Calendar <= 6.1.2.2 - Missing Authorization CVSS 4.3 · 25.07.202320.11.20235.3The Events Calendar <= 6.2.8 - Information Disclosure CVSS 5.3 · 20.11.202312.01.20245.3The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 12.01.202410.04.20244.3The Events Calendar <= 6.3.0 - Cross-Site Request Forgery to Notice Dismissal CVSS 4.3 · 10.04.202414.05.20246.1The Events Calendar <= 6.4.0 - Reflected Cross-Site Scripting CVSS 6.1 · 14.05.202424.05.20244.3The Events Calendar Free & Pro <= 6.4.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Events Access CVSS 4.3 · 24.05.202405.07.20244.3The Events Calendar <= 6.5.1.4 - Cross-Site Request Forgery via action_restore_events CVSS 4.3 · 05.07.202423.07.20247.2The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 23.07.202431.07.20244.4The Events Calendar <= 6.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 31.07.202424.09.20249.8The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection CVSS 9.8 · 24.09.202425.11.20245.3The Events Calendar <= 6.8.2 - Missing Authorization to Unauthenticated Password Protected Event Disclosure CVSS 5.3 · 25.11.202409.01.20254.3The Events Calendar <= 6.7.0 - Cross-Site Request Forgery CVSS 4.3 · 09.01.202522.01.20256.4The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.01.202519.05.20254.3The Events Calendar <= 6.11.2.1 - Missing Authorization CVSS 4.3 · 19.05.202510.06.20256.4The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CVSS 6.4 · 10.06.202511.09.20257.5The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection CVSS 7.5 · 11.09.202515.09.20255.3The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure CVSS 5.3 · 15.09.202530.10.20254.3The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure CVSS 4.3 · 30.10.202504.11.20257.5The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s CVSS 7.5 · 04.11.20255.3The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure CVSS 5.3 · 04.11.202509.01.20264.3The Events Calendar <= 6.15.12.2 - Missing Authorization CVSS 4.3 · 09.01.202620.01.20265.4The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control CVSS 5.4 · 20.01.202625.02.20265.4The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API CVSS 5.4 · 25.02.202609.03.20267.5The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import CVSS 7.5 · 09.03.202608.06.20267.5The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection CVSS 7.5 · 08.06.2026

Strategic Overview

Avg CVSSMedium
5.7/ 10
Patch Coverage100%
Open

0

Fixed

29

Get automatic notifications for all The Events Calendar vulnerabilities before they are exploited.

Vulnerability Records

29 records
2026-06-08 00:00CVE-2026-49772
7.5
High
vtimYes
2026-03-09 14:40CVE-2026-3585
7.5
High
Dmitrii IgnatyevYes
2026-02-25 08:50CVE-2026-2694
5.4
Medium
type5afeYes
2026-01-20 01:45CVE-2025-15043
5.4
Medium
type5afeYes
2026-01-09 00:00CVE-2025-69352
4.3
Medium
Phat RiOYes
2025-11-04 21:06CVE-2025-12192
5.3
Medium
mikemyersYes
2025-11-04 16:25CVE-2025-12197
7.5
High
holmeYes
2025-10-30 00:00CVE-2025-12175
4.3
Medium
Md. Moniruzzaman Prodhan (NomanProdhan)Yes
2025-09-15 16:24CVE-2025-9808
5.3
Medium
Miguel SantarenoYes
2025-09-11 12:26CVE-2025-9807
7.5
High
mikemyersYes
Showing 1–10 of 29 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C