CVE Tools

The Events Calendar

30 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for The Events Calendar, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

The Events Calendar CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
The Events Calendar CVEs per month
MonthCVEs
2024-101
2024-110
2024-122
2025-013
2025-020
2025-030
2025-040
2025-052
2025-061
2025-070
2025-080
2025-092
2025-101
2025-112
2025-120
2026-012
2026-021
2026-031
2026-040
2026-050
2026-061
2026-070
2026-081
2026-092

Severity

How the 30 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical620%
  • High517%
  • Medium1963%

Latest CVEs

The 15 most recently published vulnerabilities affecting The Events Calendar.

  1. CVE-2026-78159The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation9.8
  2. CVE-2026-78006The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution9.8
  3. CVE-2026-78265WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability9.8
  4. CVE-2026-49772WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability9.3
  5. CVE-2026-3585The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import7.5
  6. CVE-2026-2694The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API5.4
  7. CVE-2025-15043The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control5.4
  8. CVE-2025-69352WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability5.4
  9. CVE-2025-12192The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure5.3
  10. CVE-2025-12197The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s7.5
  11. CVE-2025-12175The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure4.3
  12. CVE-2025-9808The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure5.3
  13. CVE-2025-9807The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection7.5
  14. CVE-2025-5144The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting6.4
  15. CVE-2025-48246WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store