CVE-2020-35012: vulnerability in Events Manager
Events Manager < 5.9.8 - Admin+ SQL Injection
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.5%
exploitation probability
1.5%top 26% of all CVEs
observed exploitation
nono source reports it
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
Affected products
Unknown · Events ManagerRelated CVEs — Events Manager
In the same product, most dangerous first.
CVE-2020-35037—Events Manager < 5.9.8 - Cross-Site Scripting (XSS)EPSS 0.9%CVE-2026-18366CRITICALEvents Manager < 7.4.1 - Unauthenticated Privilege Escalation to AdministratorEPSS 0.5%CVE-2026-12987HIGHEvents Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEPSS 0.5%CVE-2026-18050HIGHEvents Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploadsEPSS 0.4%CVE-2026-18057HIGHEvents Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL InjectionEPSS 0.4%CVE-2026-93662MEDIUMEvents Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' ParameterEPSS 0.2%