Pricing
Case studies
Login
Start trial
Community Events
Yannick Lefebvre
Developer
1.5.9
Latest version
20
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
12 patched
5 Mitigation rules
Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field vulnerability
<= 1.5.8
07/03/2026
Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter vulnerability
<= 1.5.7
18/02/2026
Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter vulnerability
<= 1.5.6
16/01/2026
Unauthenticated SQL Injection vulnerability
<= 1.5.1
31/12/2025
Unauthenticated SQL Injection vulnerability
<= 1.5.4
18/11/2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 1.5.2
03/11/2025
Unauthenticated SQL Injection vulnerability
<= 1.5.1
07/10/2025
Admin+ Stored XSS vulnerability
< 1.5.1
05/08/2024
Event Deletion via CSRF vulnerability
< 1.5
22/07/2024
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 1.4.8
25/11/2022
SQL Injection
<= 1.3.5
21/04/2015
SQL Injection
<= 1.2.1
08/09/2011