17,305 vulnerabilities published in 2019
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
The uji-countdown plugin before 2.0.7 for WordPress has XSS.
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
The ad-buttons plugin before 2.3.2 for WordPress has XSS.
The analytics-tracker plugin before 1.1.1 for WordPress has XSS via a search event.
The booking-sms plugin before 1.1.0 for WordPress has XSS.
The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.
The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.
The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
The content-audit plugin before 1.9.2 for WordPress has XSS.
The updater plugin before 1.35 for WordPress has multiple XSS issues.
The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
The profile-builder plugin before 2.2.5 for WordPress has XSS.
The formbuilder plugin before 1.06 for WordPress has multiple XSS issues.
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
The universal-analytics plugin before 1.3.1 for WordPress has XSS.
The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen.
The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
The duplicate-post plugin before 2.6 for WordPress has XSS.
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.
The megamenu plugin before 2.4 for WordPress has XSS.
The smokesignal plugin before 1.2.7 for WordPress has XSS.
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
The embed-comment-images plugin before 0.6 for WordPress has XSS.
The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API te
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started