2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9459 | MEDIUM | 6.1 | 1.0% | Oct 10, 2019 | The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count paramete... |
| CVE-2015-9458 | HIGH | 7.2 | 1.8% | Oct 10, 2019 | The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms coun... |
| CVE-2015-9457 | HIGH | 7.2 | 1.9% | Oct 10, 2019 | The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parame... |
| CVE-2015-9456 | MEDIUM | 6.5 | 1.4% | Oct 7, 2019 | The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification vi... |
| CVE-2015-9455 | HIGH | 8.1 | 0.7% | Oct 7, 2019 | The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-ad... |
| CVE-2015-9454 | HIGH | 8.8 | 1.9% | Oct 7, 2019 | The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin ... |
| CVE-2015-9453 | MEDIUM | 6.1 | 1.5% | Oct 7, 2019 | The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL tha... |
| CVE-2015-9452 | CRITICAL | 9.8 | 2.4% | Oct 7, 2019 | The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag... |
| CVE-2015-9451 | CRITICAL | 9.8 | 2.4% | Oct 7, 2019 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p... |
| CVE-2015-9450 | CRITICAL | 9.8 | 2.2% | Oct 7, 2019 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p... |
| CVE-2015-9448 | HIGH | 8.8 | 1.9% | Sep 26, 2019 | The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid paramete... |
| CVE-2015-9447 | MEDIUM | 6.5 | 1.0% | Sep 26, 2019 | The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id... |
| CVE-2015-9446 | HIGH | 8.8 | 2.4% | Sep 26, 2019 | The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php. |
| CVE-2015-9445 | HIGH | 8.8 | 1.1% | Sep 26, 2019 | The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unite... |
| CVE-2015-9444 | MEDIUM | 6.1 | 1.1% | Sep 26, 2019 | The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/... |
| CVE-2015-9443 | MEDIUM | 6.5 | 0.8% | Sep 26, 2019 | The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/optio... |
| CVE-2015-9442 | MEDIUM | 6.5 | 0.8% | Sep 26, 2019 | The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_pl... |
| CVE-2015-9441 | MEDIUM | 6.5 | 0.8% | Sep 26, 2019 | The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify... |
| CVE-2015-9440 | MEDIUM | 6.5 | 0.8% | Sep 26, 2019 | The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-ne... |
| CVE-2015-9439 | MEDIUM | 4.8 | 1.0% | Sep 26, 2019 | The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=add... |
| CVE-2015-9438 | MEDIUM | 5.4 | 1.0% | Sep 26, 2019 | The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_ba... |
| CVE-2015-9437 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynw... |
| CVE-2015-9436 | MEDIUM | 5.4 | 1.0% | Sep 26, 2019 | The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix o... |
| CVE-2015-9435 | CRITICAL | 9.8 | 2.1% | Sep 26, 2019 | The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. |
| CVE-2015-9434 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now