Latest CVE Feed
-
8.8
HIGHCVE-2015-9394
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.... Read more
Affected Products : users_ultra_membership- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-9393
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.... Read more
Affected Products : users_ultra_membership- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-9392
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.... Read more
Affected Products : users_ultra_membership- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9391
The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.... Read more
Affected Products : yawpp- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-9390
The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.... Read more
Affected Products : admin_management_xtended- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-9389
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.... Read more
Affected Products : mtouch_quiz- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-9388
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.... Read more
Affected Products : mtouch_quiz- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-9387
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.... Read more
Affected Products : mtouch_quiz- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9386
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.... Read more
Affected Products : mtouch_quiz- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9385
The quotes-and-tips plugin before 1.20 for WordPress has XSS.... Read more
Affected Products : quotes_and_tips- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9384
The relevant plugin before 1.0.8 for WordPress has XSS.... Read more
Affected Products : relevant- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-9383
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.... Read more
- Published: Sep. 03, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-9382
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.... Read more
- Published: Sep. 03, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-9381
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.... Read more
- Published: Sep. 03, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-9380
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.... Read more
Affected Products : photo_gallery- Published: Aug. 30, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9379
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().... Read more
Affected Products : builder_style_manager- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9378
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().... Read more
Affected Products : builder_theme_market- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9377
iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().... Read more
Affected Products : builder_theme_depot- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9376
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().... Read more
Affected Products : mobile- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9375
Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().... Read more
Affected Products : table_rate_shipping- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024