Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9336 1 Codection 1 Clean Login 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
CVE-2019-15229 1 Thedaylightstudio 1 Fuel Cms 2019-08-26 6.8 MEDIUM 8.8 HIGH
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
CVE-2015-9335 1 Bestwebsoft 1 Limit Attempts 2019-08-26 7.5 HIGH 9.8 CRITICAL
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
CVE-2019-15228 1 Thedaylightstudio 1 Fuel Cms 2019-08-26 3.5 LOW 5.4 MEDIUM
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.
CVE-2013-7481 1 Bestwebsoft 1 Contact Form 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
CVE-2009-5158 1 Sumo 1 Google Analyticator 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
CVE-2019-14469 1 Sonatype 1 Nexus Repository Manager 2019-08-26 3.5 LOW 5.4 MEDIUM
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
CVE-2019-14975 1 Artifex 1 Mupdf 2019-08-26 5.8 MEDIUM 7.1 HIGH
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
CVE-2016-10917 1 Search Everything Project 1 Search Everything 2019-08-26 7.5 HIGH 9.8 CRITICAL
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
CVE-2013-7479 1 Wp-events-plugin 1 Events Manager 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
CVE-2013-7480 1 Wp-events-plugin 1 Events Manager 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
CVE-2013-7478 1 Wp-events-plugin 1 Events Manager 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
CVE-2013-7477 1 Wp-events-plugin 1 Events Manager 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
CVE-2012-6716 1 Wp-events-plugin 1 Events Manager 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
CVE-2019-15150 1 Schine.games 1 Mw-oauth2client 2019-08-26 6.8 MEDIUM 8.8 HIGH
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
CVE-2019-9648 1 Coreftp 1 Core Ftp 2019-08-26 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
CVE-2019-9649 1 Coreftp 1 Core Ftp 2019-08-26 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
CVE-2015-9320 1 Optiontree Project 1 Optiontree 2019-08-25 4.3 MEDIUM 6.1 MEDIUM
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
CVE-2017-18508 1 Wp-livechat 1 Wp Live Chat Support 2019-08-25 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
CVE-2017-1000227 1 Parallelus 1 Salutation 2019-08-24 3.5 LOW 5.4 MEDIUM
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can
CVE-2019-11522 1 Open-xchange 1 Open-xchange Appsuite 2019-08-23 3.5 LOW 5.4 MEDIUM
OX App Suite 7.10.0 to 7.10.2 allows XSS.
CVE-2017-18577 1 Ibericode 1 Mailchimp 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
CVE-2017-18576 1 Event Notifier Project 1 Event Notifier 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.
CVE-2017-18581 1 Time Sheets Project 1 Time Sheets 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.
CVE-2016-10924 1 Zedna Ebook Download Project 1 Zedna Ebook Download 2019-08-23 5.0 MEDIUM 7.5 HIGH
The ebook-download plugin before 1.2 for WordPress has directory traversal.
CVE-2016-10923 1 Visser 1 Store Toolkit For Woocommerce 2019-08-23 7.5 HIGH 9.8 CRITICAL
The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
CVE-2008-7321 1 Tubepress 1 Tubepress 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The tubepress plugin before 1.6.5 for WordPress has XSS.
CVE-2017-18580 1 Getshortcodes 1 Shortcodes Ultimate 2019-08-23 7.5 HIGH 9.8 CRITICAL
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
CVE-2017-18564 1 Bestwebsoft 1 Sender 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
CVE-2017-18563 1 Swimordiesoftware 1 Rsvp 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen.
CVE-2015-9327 1 Flickr Justified Gallery Project 1 Flickr Justified Gallery 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
CVE-2016-10929 1 Advanced Ajax Page Loader Project 1 Advanced Ajax Page Loader 2019-08-23 5.0 MEDIUM 5.3 MEDIUM
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.
CVE-2014-10392 1 Cformsii Project 1 Cformsii 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The cforms2 plugin before 10.2 for WordPress has XSS.
CVE-2017-18570 1 Cformsii Project 1 Cformsii 2019-08-23 7.5 HIGH 9.8 CRITICAL
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
CVE-2014-10393 1 Cformsii Project 1 Cformsii 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The cforms2 plugin before 10.5 for WordPress has XSS.
CVE-2017-18578 1 Crafty Social Buttons Project 1 Crafty Social Buttons 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.
CVE-2017-18585 1 Ivycat 1 Posts In Page 2019-08-23 5.5 MEDIUM 8.1 HIGH
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.
CVE-2018-20987 1 Tribulant 1 Newsletters 2019-08-23 7.5 HIGH 9.8 CRITICAL
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
CVE-2019-15328 1 Codection 1 Import Users From Csv With Meta 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
CVE-2019-15326 1 Codection 1 Import Users From Csv With Meta 2019-08-23 5.0 MEDIUM 7.5 HIGH
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
CVE-2019-15327 1 Codection 1 Import Users From Csv With Meta 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
CVE-2019-15329 1 Codection 1 Import Users From Csv With Meta 2019-08-23 6.8 MEDIUM 8.8 HIGH
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
CVE-2016-10903 1 Godaddy 1 Godaddy Email Marketing 2019-08-23 6.8 MEDIUM 8.8 HIGH
The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
CVE-2017-18521 1 Wp-kama 1 Democracy Poll 2019-08-23 6.8 MEDIUM 8.8 HIGH
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.
CVE-2017-18534 1 Share On Diaspora Project 1 Share On Diaspora 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters.
CVE-2019-14216 1 Wp Svg Icons Project 1 Wp Svg Icons 2019-08-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file.
CVE-2019-0345 1 Sap 1 Netweaver Application Server Java 2019-08-23 5.0 MEDIUM 9.8 CRITICAL
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request Forgery.
CVE-2019-0343 1 Sap 1 Commerce Cloud 2019-08-23 6.5 MEDIUM 8.8 HIGH
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
CVE-2019-15127 1 Vanderbilt 1 Redcap 2019-08-23 3.5 LOW 5.4 MEDIUM
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
CVE-2016-0785 1 Apache 1 Struts 2019-08-23 9.0 HIGH 8.8 HIGH
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.