« Back to list

Total-soft

Total-soft Event Calendar: vulnerabilities and CVEs

Total-soft Event Calendar has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-8700High (7.5)0.45%—May 15, 2025
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
CVE-2022-36390Medium (5.4)0.55%—Sep 21, 2022
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
CVE-2022-38067Medium (5.3)0.66%—Sep 9, 2022
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application1
  2. T1565.001 Stored Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Total-soft