Skip to main content

Vendor/product archive

total-soft / event_calendar CVEs

Beta · best-effort

3 CVEs tagged to total-soft / event_calendar0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-8700

Published May 15, 2025

The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36390

Published Sep 21, 2022

Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38067

Published Sep 9, 2022

Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1