17,305 vulnerabilities published in 2019
The smokesignal plugin before 1.2.7 for WordPress has XSS.
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
The embed-comment-images plugin before 0.6 for WordPress has XSS.
The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API te
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
The gnucommerce plugin before 1.4.2 for WordPress has XSS.
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library a
The tubepress plugin before 1.6.5 for WordPress has XSS.
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.
The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.
The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
The cforms2 plugin before 10.2 for WordPress has XSS.
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
The cforms2 plugin before 10.5 for WordPress has XSS.
The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.
The corner-ad plugin before 1.0.8 for WordPress has XSS.
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute,
Former before 4.2.1 has XSS via a checkbox value.
Jooby before 1.6.4 has XSS via the default error handler.
Kimai v2 before 1.1 has XSS via a timesheet description.
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
Bolt before 3.6.10 has XSS via an image's alt or title field.
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
DfE School Experience before v16333-GA has XSS via a teacher training URL.
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started