Skip to main content

Vendor archive

total-soft CVEs

Beta · best-effort

10 CVEs tagged to vendor total-soft1 Critical, 5 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2024-8700

Published May 15, 2025

The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9769

Published Dec 6, 2024

The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10247

Published Dec 6, 2024

The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and inclu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8625

Published Oct 21, 2024

The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9022

Published Oct 10, 2024

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45069

Published Nov 6, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Pl…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-25979

Published May 3, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-36390

Published Sep 21, 2022

Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38067

Published Sep 9, 2022

Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11673

Published Apr 13, 2020

An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1