Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

7,228 of 17,305 · Page 58/145
6.1
CVE-2017-18535

The smokesignal plugin before 1.2.7 for WordPress has XSS.

6.1
CVE-2017-18559

The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.

6.1
CVE-2017-18561

The embed-comment-images plugin before 0.6 for WordPress has XSS.

6.1
CVE-2017-18562

The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.

6.1
CVE-2018-20970

The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.

6.1
CVE-2018-20977

The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.

6.1
CVE-2009-5158

The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API te

6.1
CVE-2012-6716

The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.

6.1
CVE-2013-7477

The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.

6.1
CVE-2013-7478

The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.

6.1
CVE-2013-7479

The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.

6.1
CVE-2013-7480

The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.

6.1
CVE-2013-7481

The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.

6.1
CVE-2015-9336

The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

6.1
CVE-2016-10919

The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di

6.1
CVE-2016-10920

The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

6.1
CVE-2017-18572

The gnucommerce plugin before 1.4.2 for WordPress has XSS.

6.1
CVE-2017-18574

The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.

6.1
CVE-2017-18575

The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.

6.1
CVE-2018-20982

The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library a

6.1
CVE-2008-7321

The tubepress plugin before 1.6.5 for WordPress has XSS.

6.1
CVE-2013-7482

The reflex-gallery plugin before 1.4.3 for WordPress has XSS.

6.1
CVE-2014-10385

The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.

6.1
CVE-2016-10925

The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.

6.1
CVE-2017-18576

The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.

6.1
CVE-2017-18577

The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.

6.1
CVE-2017-18581

The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.

6.1
CVE-2017-18582

The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.

6.1
CVE-2018-20983

The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.

6.1
CVE-2014-10391

The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

6.1
CVE-2014-10392

The cforms2 plugin before 10.2 for WordPress has XSS.

6.1
CVE-2014-10394

The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.

6.1
CVE-2019-15331

The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.

6.1
CVE-2014-10386

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

6.1
CVE-2014-10393

The cforms2 plugin before 10.5 for WordPress has XSS.

6.1
CVE-2017-18578

The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.

6.1
CVE-2017-18579

The corner-ad plugin before 1.0.8 for WordPress has XSS.

6.1
CVE-2019-15327

The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

6.1
CVE-2019-15328

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

6.1
CVE-2019-15499

CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute,

6.1
CVE-2019-15476

Former before 4.2.1 has XSS via a checkbox value.

6.1
CVE-2019-15477

Jooby before 1.6.4 has XSS via the default error handler.

6.1
CVE-2019-15481

Kimai v2 before 1.1 has XSS via a timesheet description.

6.1
CVE-2019-15482

selectize-plugin-a11y before 1.1.0 has XSS via the msg field.

6.1
CVE-2019-15483

Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.

6.1
CVE-2019-15484

Bolt before 3.6.10 has XSS via an image's alt or title field.

6.1
CVE-2019-15485

Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.

6.1
CVE-2019-15486

django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.

6.1
CVE-2019-15487

DfE School Experience before v16333-GA has XSS via a teacher training URL.

6.1
CVE-2019-15488

Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.

Scan for 2019 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started