Skip to content
Noroxi

toolstack records

9 published records for vendor toolstack.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 23
  2. 24
  3. 25

Bar: total · dark part: CISA KEV.

Attack profile

All records

9 records
  • CVE-2024-5034
    35Monitor

    SULly < 4.3.1 - Plugin Reset via CSRF

    HighCVSS 8.8No exploitEPSS 0%

    toolstack · sullyJul 13, 2024

  • WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    toolstack · schedule posts calendarOct 6, 2023

  • CVE-2024-5151
    28Monitor

    SULly < 4.3.1 - Admin+ Stored XSS

    HighCVSS 7.1No exploitEPSS 0%

    toolstack · sullyJul 13, 2024

  • CVE-2024-5033
    23Monitor

    SULly < 4.3.1 - Admin+ Stored XSS via CSRF

    MediumCVSS 5.9No exploitEPSS 0%

    toolstack · sullyJul 13, 2024

  • CVE-2024-9662
    21Monitor

    CYAN Backup < 2.5.3 - Admin+ Stored XSS via General Settings

    MediumCVSS 5.4No exploitEPSS 0%

    toolstack · cyan backupMay 15, 2025

  • CVE-2024-9663
    21Monitor

    CYAN Backup < 2.5.3 - Admin+ Stored XSS via Remote Storage Settings

    MediumCVSS 5.4No exploitEPSS 0%

    toolstack · cyan backupMay 15, 2025

  • Auto iFrame < 2.0 - Contributor+ XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    toolstack · auto iframeJan 8, 2025

  • WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    toolstack · schedule posts calendarSep 6, 2023

  • CVE-2024-5032
    18Monitor

    SULly < 4.3.1 - Reflected XSS

    MediumCVSS 4.7No exploitEPSS 0%

    toolstack · sullyJul 13, 2024