CVE-2020-35037: vulnerability in Events Manager
Events Manager < 5.9.8 - Cross-Site Scripting (XSS)
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.9%
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
nono source reports it
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
Affected products
Unknown · Events ManagerRelated CVEs — Events Manager
In the same product, most dangerous first.
CVE-2020-35012—Events Manager < 5.9.8 - Admin+ SQL InjectionEPSS 1.5%CVE-2026-18366CRITICALEvents Manager < 7.4.1 - Unauthenticated Privilege Escalation to AdministratorEPSS 0.5%CVE-2026-12987HIGHEvents Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEPSS 0.5%CVE-2026-18050HIGHEvents Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploadsEPSS 0.4%CVE-2026-18057HIGHEvents Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL InjectionEPSS 0.4%CVE-2026-93662MEDIUMEvents Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' ParameterEPSS 0.2%