Skip to main content

Vendor archive

metagauss CVEs

Beta · best-effort

104 CVEs tagged to vendor metagauss5 Critical, 31 High, 68 Medium, 0 Low, 0 Unrated.

CVE-2024-29776

Published Mar 27, 2024

Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2951

Published Mar 26, 2024

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24832

Published Mar 23, 2024

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-29113

Published Mar 19, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects Registrat…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1321

Published Mar 13, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1127

Published Mar 13, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the booking_export_al…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1126

Published Mar 13, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_attendees_ema…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1320

Published Mar 9, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up to,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1125

Published Mar 9, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the calendar_events_del…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1124

Published Mar 9, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1123

Published Mar 9, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_fronte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51509

Published Feb 1, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, P…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6447

Published Jan 22, 2024

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36352

Published Jan 8, 2024

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Gr…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50846

Published Dec 28, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registr…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-47645

Published Nov 30, 2023

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Cross Site Re…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4252

Published Nov 27, 2023

The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47644

Published Nov 18, 2023

Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Mem…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5519

Published Oct 31, 2023

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSR…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5238

Published Oct 31, 2023

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the sear…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4251

Published Oct 31, 2023

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSR…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4250

Published Oct 31, 2023

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting whic…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45637

Published Oct 25, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3404

Published Aug 31, 2023

The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3714

Published Jul 18, 2023

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and includ…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 51-75 of 104 CVEsPage 3 of 5