17,305 vulnerabilities published in 2019
In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the p
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/sp
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg()
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on
The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
The simple-membership plugin before 3.5.7 for WordPress has XSS.
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.
The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
The twitter-plugin plugin before 2.55 for WordPress has XSS.
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
The events-manager plugin before 5.6 for WordPress has XSS.
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
The simple-fields plugin before 1.4.11 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and fil
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.
The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
The liveforms plugin before 3.4.0 for WordPress has XSS.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started