Vulnerabilities (CVE)

Filtered by vendor E-dynamics Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24813 1 E-dynamics 1 Events Made Easy 2021-11-02 3.5 LOW 4.8 MEDIUM
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed