17,305 vulnerabilities published in 2019
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
The gnucommerce plugin before 1.4.2 for WordPress has XSS.
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library a
The tubepress plugin before 1.6.5 for WordPress has XSS.
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.
The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.
The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
The cforms2 plugin before 10.2 for WordPress has XSS.
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
The cforms2 plugin before 10.5 for WordPress has XSS.
The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.
The corner-ad plugin before 1.0.8 for WordPress has XSS.
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute,
Former before 4.2.1 has XSS via a checkbox value.
Jooby before 1.6.4 has XSS via the default error handler.
Kimai v2 before 1.1 has XSS via a timesheet description.
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
Bolt before 3.6.10 has XSS via an image's alt or title field.
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
DfE School Experience before v16333-GA has XSS via a teacher training URL.
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or Java
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from ve
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the us
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open r
Status Board 1.1.81 has reflected XSS via logic.ts.
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
Status Board 1.1.81 has reflected XSS via dashboard.ts.
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage t
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
The wp-rollback plugin before 1.2.3 for WordPress has XSS.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started