All 4 CVE vulnerabilities found in Total, with AI-generated Chinese analysis, references, and POCs.
Vendor: hashthemes
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-5077 | Total <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title in Blog Section Image alt Attribute CWE-79 | 5.4 | Medium | 2026-05-02 |
| CVE-2023-27456 | WordPress Total theme <= 2.1.19 - Authenticated Arbitrary Plugin Activation CWE-862 | 4.3 | Medium | 2024-12-13 |
| CVE-2024-7240 | F-Secure Total Link Following Local Privilege Escalation Vulnerability CWE-59 | 6.5 | - | 2024-11-22 |
| CVE-2024-1771 | Total <= 2.1.59 - Missing Authorization to Authenticated (Subscriber+) Sections Update CWE-862 | 4.3 | Medium | 2024-03-06 |
All 4 known CVE vulnerabilities affecting Total with full Chinese analysis, references, and POCs where available.