VideoPRO CMS version 2.0 appears to leave default credentials installed after installation.
606cb5d5f4b1d59e6f6e304f8f83376c5f2b3755fbf7af593acf7e03667ea985
WordPress EventON Calendar plugin version 4.4 suffers from an insecure direct object reference vulnerability related to posting.
2f87612cff5b66dcbd6a5886fbc280b3873c37bd95eb601dfb54cb6abd4f70f2