17,305 vulnerabilities published in 2019
The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.
The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288.
The realty plugin before 1.1.0 for WordPress has multiple XSS issues.
The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.
The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This co
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This c
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This co
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
The seo-redirection plugin before 4.3 for WordPress has stored XSS.
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
The total-security plugin before 3.4.1 for WordPress has XSS.
The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters.
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
The uji-countdown plugin before 2.0.7 for WordPress has XSS.
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
The ad-buttons plugin before 2.3.2 for WordPress has XSS.
The analytics-tracker plugin before 1.1.1 for WordPress has XSS via a search event.
The booking-sms plugin before 1.1.0 for WordPress has XSS.
The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.
The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.
The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
The content-audit plugin before 1.9.2 for WordPress has XSS.
The updater plugin before 1.35 for WordPress has multiple XSS issues.
The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
The profile-builder plugin before 2.2.5 for WordPress has XSS.
The formbuilder plugin before 1.06 for WordPress has multiple XSS issues.
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
The universal-analytics plugin before 1.3.1 for WordPress has XSS.
The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen.
The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
The duplicate-post plugin before 2.6 for WordPress has XSS.
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.
The megamenu plugin before 2.4 for WordPress has XSS.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started