CVE Tools

Eventon

28 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Eventon, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Eventon CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Eventon CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-042
2025-054
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 28 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High414%
  • Medium2486%

Latest CVEs

The 15 most recently published vulnerabilities affecting Eventon.

  1. CVE-2026-81791WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability6.5
  2. CVE-2026-28037WordPress EventON plugin <= 4.9.12 - Reflected Cross Site Scripting (XSS) vulnerability7.1
  3. CVE-2025-63064WordPress EventON plugin <= 4.9.12 - Cross Site Scripting (XSS) vulnerability6.5
  4. CVE-2025-47565WordPress EventON plugin <= 4.9.9 - Broken Access Control vulnerability6.3
  5. CVE-2025-3527EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting6.4
  6. CVE-2025-47564WordPress EventON plugin <= 4.9.8 - Broken Access Control vulnerability5.3
  7. CVE-2025-48116WordPress EventON plugin <= 2.4.4 - Broken Access Control Vulnerability5.3
  8. CVE-2025-47494WordPress EventON plugin <= 2.4.1 - Local File Inclusion Vulnerability7.5
  9. CVE-2025-32614WordPress EventON plugin <= 2.4 - Local File Inclusion vulnerability8.8
  10. CVE-2025-32160WordPress EventON plugin <= 2.4.1 - Local File Inclusion vulnerability7.5
  11. CVE-2024-6910EventON < 2.2.17 - Admin+ Stored XSS4.8
  12. CVE-2024-4752EventON < 2.2.15 - Admin+ Stored Cross-Site Scripting via event subtitle5.9
  13. CVE-2024-33940WordPress EventON plugin <= 2.2.14 - Cross Site Scripting (XSS) vulnerability5.9
  14. CVE-2023-7200EventON < 4.4.1 - Reflected Cross-Site Scripting6.1
  15. CVE-2024-0238EventON (Free < 2.2.8, Premium < 4.5.6) - Unauthenticated Arbitrary Post Metadata Update6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store