Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-8700 The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitr… Event Calendar after 1.0.4 Fix from $1,9502025-05-15 HIGH 7.2 CVE-2024-8625 The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQ… Ts Poll 2.4.0+ Fix from $1,9502024-10-21 HIGH 7.2 CVE-2024-9022 The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all vers… Ts Poll 2.4.1+ Fix from $1,9502024-10-10 CRITICAL 9.8 CVE-2023-45069 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Bes… Video Gallery after 2.1.4 Fix from $2,3002023-11-06 MEDIUM 5.4 CVE-2022-36390 Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. Event Calendar after 1.4.6 Fix from $1,6002022-09-21 MEDIUM 5.3 CVE-2022-38067 Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. Event Calendar after 1.4.6 Fix from $1,6002022-09-09 CRITICAL 9.8 CVE-2020-11673 An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clon… Responsive Poll after 1.3.4 Fix from $2,3002020-04-13