Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tri

First CVE: May 27, 2015Active for: 11 yearsTotal CVEs: 9

Tri's vulnerability profile centers on a small portfolio of WordPress plugins focused on event management and page building, including GigPress, Event Tickets, Panel Builder, and The Events Calendar. The recurring exposure reflects common application-layer input-handling weaknesses—cross-site scripting, SQL injection, open redirects, and related neutralization gaps—that are characteristic of web-facing plugins with user-supplied content and database interaction, and the vendor's disclosures have an elevated tendency toward public exploit availability. Defenders tracking WordPress environments should monitor this vendor's advisories and prioritize patching in internet-reachable event management deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tri over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 27, 2015
11 years ago
Most Recent CVE
Jun 14, 2024
771 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25028MEDIUM
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary re
Jan 24, 20226.132NOYES
CVE-2015-4066MEDIUM
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands vi
May 27, 20156.527NOYES
CVE-2023-0381HIGH
The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated
Feb 27, 20238.826NONO
CVE-2020-36626MEDIUM
A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularCont
Dec 27, 20226.122NONO
CVE-2015-9353HIGH
The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066.
Aug 28, 20197.219NONO
CVE-2024-1295MEDIUM
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking
Jun 14, 20246.518NONO
CVE-2023-7233MEDIUM
The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Sc
Feb 12, 20244.816NONO
CVE-2022-4759MEDIUM
The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, w
Feb 13, 20235.416NONO
CVE-2015-9354MEDIUM
The gigpress plugin before 2.3.11 for WordPress has XSS.
Aug 28, 20194.815NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
78%
22%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None3 (33.3%)
Unknown1 (11.1%)
Required5 (55.6%)
Privileges Required
Low3 (33.3%)
High3 (33.3%)
None2 (22.2%)
Unknown1 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tri.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tri — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tri's Products

View all 3 CNAs →

Top CWEs