17,305 vulnerabilities published in 2019
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
The simple-membership plugin before 3.5.7 for WordPress has XSS.
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.
The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
The twitter-plugin plugin before 2.55 for WordPress has XSS.
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
The events-manager plugin before 5.6 for WordPress has XSS.
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
The simple-fields plugin before 1.4.11 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and fil
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.
The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
The liveforms plugin before 3.4.0 for WordPress has XSS.
The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.
The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues.
SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some
Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1,
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficien
The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started