Search Results (20777 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-10880 1 Google Doc Embedder Project 1 Google Doc Embedder 2024-11-21 N/A
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
CVE-2016-10879 1 3cx 1 Live Chat 2024-11-21 N/A
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
CVE-2016-10877 1 Wp Editor Project 1 Wp Editor 2024-11-21 N/A
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
CVE-2016-10876 1 Wpseeds 1 Wp Database Backup 2024-11-21 N/A
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
CVE-2016-10875 1 Wpseeds 1 Wp Database Backup 2024-11-21 6.1 Medium
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
CVE-2016-10874 1 Wpseeds 1 Wp Database Backup 2024-11-21 8.8 High
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
CVE-2016-10873 1 Wpseeds 1 Wp Database Backup 2024-11-21 6.1 Medium
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
CVE-2016-10872 1 Ultimatemember 1 Ultimate Member 2024-11-21 6.1 Medium
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
CVE-2016-10870 1 Gtranslate 1 Google Language Translator 2024-11-21 N/A
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
CVE-2016-10869 1 Bestwebsoft 1 Contact Form 2024-11-21 N/A
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
CVE-2016-10868 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 N/A
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
CVE-2016-10867 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 6.1 Medium
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
CVE-2016-10866 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 N/A
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
CVE-2016-10865 1 23systems 1 Lightbox Plus Colorbox 2024-11-21 N/A
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
CVE-2016-10763 1 Automattic 1 Camptix Event Ticketing 2024-11-21 N/A
The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.
CVE-2016-10762 1 Automattic 1 Camptix Event Ticketing 2024-11-21 N/A
The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.
CVE-2016-10736 1 Devpups 1 Social Pug 2024-11-21 N/A
The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
CVE-2016-10706 1 Automattic 1 Jetpack 2024-11-21 N/A
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
CVE-2016-10705 1 Automattic 1 Jetpack 2024-11-21 N/A
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
CVE-2016-0796 1 Mb.miniaudioplayer Project 1 Mb.miniaudioplayer 2024-11-21 7.5 High
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind vulnerable website or to perform otherwise restricted actions and subsequently download files with the extension mp3, mp4a, wav and ogg from anywhere the web server application has read access to the system. WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files version 1.7.6 is vulnerable; prior versions may also be affected.