Total-Soft records
10 published records for vendor total-soft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-306 Missing Authentication for Critical Function1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-11673No exploit | An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress.total-soft · responsive poll · CWE-306 | Critical9.8 | — | 3.5% | Apr 13, 2020 |
39Monitor | CVE-2023-45069No exploit | WordPress Video Gallery – YouTube Gallery Plugin <= 2.1.3 is vulnerable to SQL Injectiontotal-soft · video gallery · CWE-89 | Critical9.8 | — | 0.5% | Nov 6, 2023 |
30Monitor | CVE-2024-8700No exploit | Event Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar Deletiontotal-soft · event calendar · CWE-862 | High7.5 | — | 0.5% | May 15, 2025 |
29Monitor | CVE-2024-8625Proof of concept | TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injectiontotal-soft · ts poll · CWE-89 | High7.2 | — | 2.3% | Oct 21, 2024 |
28Monitor | CVE-2024-9022No exploit | TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parametertotal-soft · ts poll · CWE-89 | High7.2 | — | 1.0% | Oct 9, 2024 |
21Monitor | CVE-2022-38067No exploit | WordPress Event Calendar – Calendar plugin <= 1.4.6 - Unauthenticated Event Deletion vulnerabilitytotal-soft · event calendar · CWE-264 | Medium5.3 | — | 0.7% | Sep 9, 2022 |
21Monitor | CVE-2022-36390No exploit | WordPress Event Calendar – Calendar plugin <= 1.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilitytotal-soft · event calendar · CWE-79 | Medium5.4 | — | 0.5% | Sep 21, 2022 |
19Monitor | CVE-2024-10247No exploit | YouTube Gallery and Vimeo Gallery Plugin <= 2.4.2 - Authenticated (Administrator+) SQL Injectiontotal-soft · video gallery · CWE-89 | Medium4.9 | — | 0.5% | Dec 6, 2024 |
19Monitor | CVE-2023-25979No exploit | WordPress Video Gallery – YouTube Gallery Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)total-soft · video gallery · CWE-79 | Medium4.8 | — | 0.4% | May 3, 2023 |
19Monitor | CVE-2024-9769No exploit | Video Gallery <= 2.4.1 - Authenticated (Administrator+) Stored Cross-Site Scriptingtotal-soft · video gallery · CWE-79 | Medium4.8 | — | 0.3% | Dec 6, 2024 |
- CVE-2020-1167340Plan
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress.
CriticalCVSS 9.8No exploitEPSS 4%total-soft · responsive pollApr 13, 2020
- CVE-2023-4506939Monitor
WordPress Video Gallery – YouTube Gallery Plugin <= 2.1.3 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%total-soft · video galleryNov 6, 2023
- CVE-2024-870030Monitor
Event Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar Deletion
HighCVSS 7.5No exploitEPSS 0%total-soft · event calendarMay 15, 2025
- CVE-2024-862529Monitor
TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
HighCVSS 7.2Proof of conceptEPSS 2%total-soft · ts pollOct 21, 2024
- CVE-2024-902228Monitor
TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter
HighCVSS 7.2No exploitEPSS 1%total-soft · ts pollOct 9, 2024
- CVE-2022-3806721Monitor
WordPress Event Calendar – Calendar plugin <= 1.4.6 - Unauthenticated Event Deletion vulnerability
MediumCVSS 5.3No exploitEPSS 1%total-soft · event calendarSep 9, 2022
- CVE-2022-3639021Monitor
WordPress Event Calendar – Calendar plugin <= 1.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 1%total-soft · event calendarSep 21, 2022
- CVE-2024-1024719Monitor
YouTube Gallery and Vimeo Gallery Plugin <= 2.4.2 - Authenticated (Administrator+) SQL Injection
MediumCVSS 4.9No exploitEPSS 1%total-soft · video galleryDec 6, 2024
- CVE-2023-2597919Monitor
WordPress Video Gallery – YouTube Gallery Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%total-soft · video galleryMay 3, 2023
- CVE-2024-976919Monitor
Video Gallery <= 2.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 0%total-soft · video galleryDec 6, 2024