17,305 vulnerabilities published in 2019
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component,
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes para
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGallery
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
The xo-security plugin before 1.5.3 for WordPress has XSS.
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IM
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead t
Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
The moreads-se plugin before 1.4.7 for WordPress has XSS.
The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.
The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.
The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.
The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288.
The realty plugin before 1.1.0 for WordPress has multiple XSS issues.
The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.
The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This co
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This c
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This co
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
The seo-redirection plugin before 4.3 for WordPress has stored XSS.
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
The total-security plugin before 3.4.1 for WordPress has XSS.
The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started