mage-people CVE Vulnerabilities & Metrics

Focus on mage-people vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About mage-people Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with mage-people. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total mage-people CVEs: 9
Earliest CVE date: 14 Mar 2022, 15:15 UTC
Latest CVE date: 17 Sep 2024, 23:15 UTC

Latest CVE reference: CVE-2024-43985

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -60.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -60.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical mage-people CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.72

Max CVSS: 6.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 1
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS mage-people CVEs

These are the five CVEs with the highest CVSS scores for mage-people, sorted by severity first and recency.

All CVEs for mage-people

CVE-2024-43985 mage-people vulnerability CVSS: 0 17 Sep 2024, 23:15 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Bus Ticket Booking with Seat Reservation allows Stored XSS.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through 5.3.5.

CVE-2024-43138 mage-people vulnerability CVSS: 0 13 Aug 2024, 12:15 UTC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.

CVE-2024-24796 mage-people vulnerability CVSS: 0 12 Feb 2024, 08:15 UTC

Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.

CVE-2023-30496 mage-people vulnerability CVSS: 0 22 Nov 2023, 20:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team WpBusTicketly plugin <= 5.2.5 versions.

CVE-2023-4067 mage-people vulnerability CVSS: 0 02 Aug 2023, 09:15 UTC

The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-36383 mage-people vulnerability CVSS: 0 18 Jul 2023, 15:15 UTC

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.

CVE-2023-28422 mage-people vulnerability CVSS: 0 23 Mar 2023, 12:15 UTC

Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.

CVE-2023-0144 mage-people vulnerability CVSS: 0 06 Feb 2023, 20:15 UTC

The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-0478 mage-people vulnerability CVSS: 6.5 14 Mar 2022, 15:15 UTC

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks