Search Results (20782 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-16525 1 Checklist 1 Checklist 2024-11-21 6.1 Medium
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.
CVE-2019-16524 1 Status301 1 Easy Fancybox 2024-11-21 4.8 Medium
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.
CVE-2019-16523 1 Pixelite 1 Events Manager 2024-11-21 5.4 Medium
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.
CVE-2019-16522 1 Eu Cookie Law Project 1 Eu Cookie Law 2024-11-21 4.8 Medium
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users.
CVE-2019-16521 1 Managewp 1 Broken Link Checker 2024-11-21 6.1 Medium
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the s_filter GET parameter in a filter_id=search request. NOTE: this is an end-of-life product.
CVE-2019-16520 1 Semperplugins 1 All In One Seo Pack 2024-11-21 5.4 Medium
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.
CVE-2019-16332 1 Api Bearer Auth Project 1 Api Bearer Auth 2024-11-21 6.1 Medium
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
CVE-2019-16289 1 Webcraftic 1 Woody Ad Snippets 2024-11-21 5.4 Medium
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
CVE-2019-16251 1 Yithemes 38 Yith Advanced Refund System For Woocommerce, Yith Color And Label Variations For Woocommerce, Yith Custom Thank You Page For Woocommerce and 35 more 2024-11-21 4.3 Medium
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
CVE-2019-16250 1 Oceanwp 1 Ocean Extra 2024-11-21 7.5 High
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
CVE-2019-16223 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 5.4 Medium
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-16222 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 6.1 Medium
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
CVE-2019-16221 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 6.1 Medium
WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVE-2019-16220 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 6.1 Medium
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
CVE-2019-16219 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 6.1 Medium
WordPress before 5.2.3 allows XSS in shortcode previews.
CVE-2019-16218 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 6.1 Medium
WordPress before 5.2.3 allows XSS in stored comments.
CVE-2019-16217 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 6.1 Medium
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
CVE-2019-16119 1 10web 1 Photo Gallery 2024-11-21 9.8 Critical
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
CVE-2019-16118 1 10web 1 Photo Gallery 2024-11-21 6.1 Medium
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
CVE-2019-16117 1 10web 1 Photo Gallery 2024-11-21 6.1 Medium
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.