Toolstack's vulnerability footprint centers on a modest set of web-facing applications including Sully, Cyan Backup, Schedule Posts Calendar, and Auto iFrame, with a durable signal anchored in application-layer input-handling weaknesses such as cross-site scripting and cross-site request forgery. These weakness classes are characteristic of web application development and reflect the typical attack surface of customer-facing or administrative tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Toolstack over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5034HIGH The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | Jul 13, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-40556HIGH Cross-Site Request Forgery (CSRF) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions. | Oct 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-5151HIGH The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripti | Jul 13, 2024 | 7.1 | 20 | NO | NO |
CVE-2024-10151MEDIUM The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, w | Jan 8, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-5033MEDIUM The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admi | Jul 13, 2024 | 5.9 | 17 | NO | NO |
CVE-2023-40560MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions. | Sep 6, 2023 | 4.8 | 17 | NO | NO |
CVE-2024-9663MEDIUM The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site S | May 15, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-9662MEDIUM The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site S | May 15, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-5032MEDIUM The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be u | Jul 13, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toolstack.
Media articles that mention a CVE ID that affects a product developed by Toolstack — matched by CVE ID, not by vendor name.