2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-9459MEDIUM6.1The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count paramete...
CVE-2015-9458HIGH7.2The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms coun...
CVE-2015-9457HIGH7.2The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parame...
CVE-2015-9456MEDIUM6.5The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification vi...
CVE-2015-9455HIGH8.1The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-ad...
CVE-2015-9454HIGH8.8The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin ...
CVE-2015-9453MEDIUM6.1The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL tha...
CVE-2015-9452CRITICAL9.8The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag...
CVE-2015-9451CRITICAL9.8The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p...
CVE-2015-9450CRITICAL9.8The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p...
CVE-2015-9448HIGH8.8The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid paramete...
CVE-2015-9447MEDIUM6.5The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id...
CVE-2015-9446HIGH8.8The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
CVE-2015-9445HIGH8.8The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unite...
CVE-2015-9444MEDIUM6.1The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/...
CVE-2015-9443MEDIUM6.5The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/optio...
CVE-2015-9442MEDIUM6.5The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_pl...
CVE-2015-9441MEDIUM6.5The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify...
CVE-2015-9440MEDIUM6.5The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-ne...
CVE-2015-9439MEDIUM4.8The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=add...
CVE-2015-9438MEDIUM5.4The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_ba...
CVE-2015-9437MEDIUM6.5The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynw...
CVE-2015-9436MEDIUM5.4The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix o...
CVE-2015-9435CRITICAL9.8The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
CVE-2015-9434MEDIUM6.5The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now