Search Results (18007 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2015-9303 1 Simplesharebuttons 1 Simple Share Buttons Adder 2024-11-21 N/A
The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
CVE-2015-9302 1 Simple Fields Project 1 Simple Fields 2024-11-21 6.1 Medium
The simple-fields plugin before 1.4.11 for WordPress has XSS.
CVE-2015-9301 1 W3eden 1 Live Forms 2024-11-21 N/A
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
CVE-2015-9300 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
CVE-2015-9299 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
CVE-2015-9298 1 Pixelite 1 Events Manager 2024-11-21 9.8 Critical
The events-manager plugin before 5.6 for WordPress has code injection.
CVE-2015-9297 1 Pixelite 1 Events Manager 2024-11-21 6.1 Medium
The events-manager plugin before 5.6 for WordPress has XSS.
CVE-2015-9296 1 Never5 1 Download Monitor 2024-11-21 N/A
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
CVE-2015-9295 1 Bestwebsoft 1 Contact Form 2024-11-21 N/A
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
CVE-2015-9294 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 N/A
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
CVE-2015-9293 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 N/A
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
CVE-2015-9273 1 Wp-slimstat 1 Slimstat Analytics 2024-11-21 N/A
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking.
CVE-2015-9272 1 Videowhisper 1 Video Presentation 2024-11-21 N/A
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
CVE-2015-9271 1 Videowhisper 1 Video Conference 2024-11-21 N/A
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905.
CVE-2015-9270 1 Theholidaycalendar 1 Holiday Calendar 2024-11-21 N/A
XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter.
CVE-2015-9269 1 Wpmobilepack 1 Wordpress Mobile Pack 2024-11-21 N/A
The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obtain sensitive information because the content of a privately published post is sent in JSON format.
CVE-2015-5484 1 Plot 1 Plotly 2024-11-21 5.4 Medium
Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.
CVE-2015-5483 1 Private Only Project 1 Private Only 2024-11-21 8.8 High
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or (4) conduct cross-site scripting (XSS) attacks via the po_logo parameter in the privateonly.php page to wp-admin/options-general.php.
CVE-2015-4617 1 Easy2map 1 Easy2map-photos 2024-11-21 N/A
Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.
CVE-2015-4615 1 Easy2map 1 Easy2map-photos 2024-11-21 N/A
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables