2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-9484HIGH7.5The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obt...
CVE-2015-9483HIGH7.5The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remot...
CVE-2015-9482HIGH7.5The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to ob...
CVE-2015-9481HIGH7.5The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive ...
CVE-2015-9480HIGH7.5The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
CVE-2015-9479CRITICAL9.8The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request ...
CVE-2015-9478MEDIUM6.1prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.
CVE-2015-9477HIGH8.8The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
CVE-2015-9476HIGH8.8The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
CVE-2015-9475HIGH8.8The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
CVE-2015-9474HIGH8.8The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
CVE-2015-9473HIGH7.5The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo...
CVE-2015-9472MEDIUM6.1The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.
CVE-2015-9471CRITICAL9.8The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
CVE-2015-9470HIGH7.5The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
CVE-2015-9469MEDIUM4.8The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
CVE-2015-9468MEDIUM6.1The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
CVE-2015-9467CRITICAL9.8The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parame...
CVE-2015-9466CRITICAL9.8The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTT...
CVE-2015-9465HIGH8.8The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via...
CVE-2015-9463HIGH7.5The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/u...
CVE-2015-9464HIGH7.5The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets...
CVE-2015-9462HIGH7.2The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat...
CVE-2015-9461HIGH7.2The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via t...
CVE-2015-9460HIGH8.8The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now