Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Event Calendar HIGH 7.5
CVE-2024-8700

The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitr…

Fix: after 1.0.4
Fix from $1,950 2025-05-15
Ts Poll HIGH 7.2
CVE-2024-8625

The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQ…

Fix: 2.4.0+
Fix from $1,950 2024-10-21
Ts Poll HIGH 7.2
CVE-2024-9022

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all vers…

Fix: 2.4.1+
Fix from $1,950 2024-10-10
Video Gallery CRITICAL 9.8
CVE-2023-45069

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Bes…

Fix: after 2.1.4
Fix from $2,300 2023-11-06
Event Calendar MEDIUM 5.4
CVE-2022-36390

Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

Fix: after 1.4.6
Fix from $1,600 2022-09-21
Event Calendar MEDIUM 5.3
CVE-2022-38067

Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

Fix: after 1.4.6
Fix from $1,600 2022-09-09
Responsive Poll CRITICAL 9.8
CVE-2020-11673

An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clon…

Fix: after 1.3.4
Fix from $2,300 2020-04-13