Vollstart maintains a ticketing and event-management platform with integrated scanning capabilities, where its vulnerability footprint centers on web-application input-handling defects. The recurring issues span cross-site scripting, cross-site request forgery, code injection, and related neutralization weaknesses that are typical of web-facing applications processing user-supplied event and ticket data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vollstart over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68015CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This | Jan 22, 2026 | 9.0 | 27 | NO | NO |
CVE-2024-52427HIGH Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This iss | Nov 18, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-35652MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.Thi | Jun 4, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-1762MEDIUM The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in ad | Mar 28, 2025 | 4.3 | 15 | NO | NO |
The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cro | May 15, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vollstart.
Media articles that mention a CVE ID that affects a product developed by Vollstart — matched by CVE ID, not by vendor name.