Latest CVE Feed
-
6.1
MEDIUMCVE-2015-9539
The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.... Read more
Affected Products : fast_secure_contact_form- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-9538
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.... Read more
Affected Products : nextgen_gallery- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-9537
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.... Read more
Affected Products : nextgen_gallery- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9504
The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.... Read more
Affected Products : weeklynews_theme- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9503
The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier.... Read more
Affected Products : modern_theme- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9502
The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier.... Read more
Affected Products : auberge_theme- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9501
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.... Read more
Affected Products : artificial_intelligence- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9500
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.... Read more
Affected Products : exquisite_ultimate_newspaper- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-9499
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.... Read more
Affected Products : showbiz_pro- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-9498
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.... Read more
Affected Products : wps_hide_login- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-9497
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.... Read more
Affected Products : ad_inserter- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-9496
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.... Read more
Affected Products : freshmail-newsletter- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9495
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.... Read more
Affected Products : syndication_links- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9494
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.... Read more
Affected Products : indieweb_post_kinds- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9493
The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.... Read more
Affected Products : my_wish_list- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9492
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate... Read more
Affected Products : smartit_premium_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9491
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrat... Read more
Affected Products : blessing_premium_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9490
The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_user... Read more
Affected Products : gamestheme_premium- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9489
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate... Read more
Affected Products : goodnex_premium_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9488
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/upl... Read more
Affected Products : almera_responsive_portfolio_site_template- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024