Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-5329 | 1 Redirection | 1 Redirection | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562. | |||||
CVE-2012-6717 | 1 Redirection | 1 Redirection | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562. | |||||
CVE-2015-9359 | 1 Automattic | 1 Jetpack | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2015-9360 | 1 Updraftplus | 1 Updraftplus | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2017-18593 | 1 Updraftplus | 1 Updraftplus | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file. | |||||
CVE-2015-9356 | 1 Wp-vipergb Project | 1 Wp-vipergb | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue than CVE-2014-9460. | |||||
CVE-2019-15230 | 1 Librenms | 1 Librenms | 2019-08-30 | 3.5 LOW | 5.4 MEDIUM |
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account. | |||||
CVE-2015-9364 | 1 2checkout | 1 Ithemes 2checkout | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2015-9362 | 1 Never5 | 1 Post Connector | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2015-9363 | 1 Ithemes | 1 Exchange | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2015-9365 | 1 Ithemes | 1 Authorize.net | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2015-9361 | 1 Never5 | 1 Related Posts | 2019-08-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2015-9376 | 1 Ithemes | 1 Mobile | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |||||
CVE-2019-15713 | 1 My Calendar Project | 1 My Calendar | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
The my-calendar plugin before 3.1.10 for WordPress has XSS. | |||||
CVE-2018-16256 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
CVE-2018-16257 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
** DISPUTED ** There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
CVE-2018-16255 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
CVE-2018-16258 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
CVE-2018-16259 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
CVE-2015-9357 | 1 Automattic | 1 Akismet | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
The akismet plugin before 3.1.5 for WordPress has XSS. |