Vulnerabilities (CVE)

Filtered by vendor E-dynamics Subscribe
Filtered by product Events Made Easy
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1905 1 E-dynamics 1 Events Made Easy 2022-06-28 7.5 HIGH 9.8 CRITICAL
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection