toolstack records
9 published records for vendor toolstack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-5034No exploit | SULly < 4.3.1 - Plugin Reset via CSRFtoolstack · sully · CWE-352 | High8.8 | — | 0.4% | Jul 13, 2024 |
35Monitor | CVE-2023-40556No exploit | WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Request Forgery (CSRF)toolstack · schedule posts calendar · CWE-352 | High8.8 | — | 0.3% | Oct 6, 2023 |
28Monitor | CVE-2024-5151No exploit | SULly < 4.3.1 - Admin+ Stored XSStoolstack · sully · CWE-79 | High7.1 | — | 0.4% | Jul 13, 2024 |
23Monitor | CVE-2024-5033No exploit | SULly < 4.3.1 - Admin+ Stored XSS via CSRFtoolstack · sully · CWE-352 | Medium5.9 | — | 0.2% | Jul 13, 2024 |
21Monitor | CVE-2024-9662No exploit | CYAN Backup < 2.5.3 - Admin+ Stored XSS via General Settingstoolstack · cyan backup · CWE-79 | Medium5.4 | — | 0.3% | May 15, 2025 |
21Monitor | CVE-2024-9663No exploit | CYAN Backup < 2.5.3 - Admin+ Stored XSS via Remote Storage Settingstoolstack · cyan backup · CWE-79 | Medium5.4 | — | 0.3% | May 15, 2025 |
21Monitor | CVE-2024-10151No exploit | Auto iFrame < 2.0 - Contributor+ XSS via Shortcodetoolstack · auto iframe · CWE-79 | Medium5.4 | — | 0.3% | Jan 8, 2025 |
19Monitor | CVE-2023-40560No exploit | WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Scripting (XSS)toolstack · schedule posts calendar · CWE-79 | Medium4.8 | — | 0.4% | Sep 6, 2023 |
18Monitor | CVE-2024-5032No exploit | SULly < 4.3.1 - Reflected XSStoolstack · sully · CWE-79 | Medium4.7 | — | 0.5% | Jul 13, 2024 |
- CVE-2024-503435Monitor
SULly < 4.3.1 - Plugin Reset via CSRF
HighCVSS 8.8No exploitEPSS 0%toolstack · sullyJul 13, 2024
- CVE-2023-4055635Monitor
WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%toolstack · schedule posts calendarOct 6, 2023
- CVE-2024-515128Monitor
SULly < 4.3.1 - Admin+ Stored XSS
HighCVSS 7.1No exploitEPSS 0%toolstack · sullyJul 13, 2024
- CVE-2024-503323Monitor
SULly < 4.3.1 - Admin+ Stored XSS via CSRF
MediumCVSS 5.9No exploitEPSS 0%toolstack · sullyJul 13, 2024
- CVE-2024-966221Monitor
CYAN Backup < 2.5.3 - Admin+ Stored XSS via General Settings
MediumCVSS 5.4No exploitEPSS 0%toolstack · cyan backupMay 15, 2025
- CVE-2024-966321Monitor
CYAN Backup < 2.5.3 - Admin+ Stored XSS via Remote Storage Settings
MediumCVSS 5.4No exploitEPSS 0%toolstack · cyan backupMay 15, 2025
- CVE-2024-1015121Monitor
Auto iFrame < 2.0 - Contributor+ XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 0%toolstack · auto iframeJan 8, 2025
- CVE-2023-4056019Monitor
WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%toolstack · schedule posts calendarSep 6, 2023
- CVE-2024-503218Monitor
SULly < 4.3.1 - Reflected XSS
MediumCVSS 4.7No exploitEPSS 0%toolstack · sullyJul 13, 2024