17,305 vulnerabilities published in 2019
The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.
The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues.
SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some
Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1,
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficien
The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component,
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes para
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGallery
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
The xo-security plugin before 1.5.3 for WordPress has XSS.
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IM
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead t
Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
The moreads-se plugin before 1.4.7 for WordPress has XSS.
The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.
The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started