2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9433 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration paramet... |
| CVE-2015-9432 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/opt... |
| CVE-2015-9431 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page... |
| CVE-2015-9449 | HIGH | 7.2 | 1.9% | Sep 26, 2019 | The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=micro... |
| CVE-2015-9430 | MEDIUM | 6.1 | 1.4% | Sep 26, 2019 | The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header. |
| CVE-2015-9429 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page... |
| CVE-2015-9428 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-... |
| CVE-2015-9427 | MEDIUM | 6.5 | 1.1% | Sep 26, 2019 | The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=... |
| CVE-2015-9426 | MEDIUM | 4.6 | 1.0% | Sep 26, 2019 | The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?actio... |
| CVE-2015-9425 | MEDIUM | 5.4 | 0.7% | Sep 26, 2019 | The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opan... |
| CVE-2015-9424 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=mult... |
| CVE-2015-9423 | MEDIUM | 5.4 | 1.0% | Sep 26, 2019 | The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields... |
| CVE-2015-9422 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?... |
| CVE-2015-9421 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?a... |
| CVE-2015-9420 | MEDIUM | 6.1 | 1.4% | Sep 26, 2019 | The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_p... |
| CVE-2015-9419 | MEDIUM | 6.1 | 1.2% | Sep 26, 2019 | The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section. |
| CVE-2015-9418 | MEDIUM | 4.3 | 0.6% | Sep 26, 2019 | The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes. |
| CVE-2015-9417 | MEDIUM | 6.5 | 0.7% | Sep 26, 2019 | The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS. |
| CVE-2015-9416 | MEDIUM | 6.1 | 1.0% | Sep 26, 2019 | The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header. |
| CVE-2015-9415 | HIGH | 7.5 | 3.4% | Sep 26, 2019 | The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion. |
| CVE-2015-9414 | MEDIUM | 6.1 | 3.6% | Sep 26, 2019 | The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?... |
| CVE-2015-9413 | MEDIUM | 6.5 | 1.1% | Sep 26, 2019 | The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-download... |
| CVE-2015-9412 | MEDIUM | 6.1 | 1.2% | Sep 26, 2019 | The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter. |
| CVE-2015-9411 | MEDIUM | 6.1 | 1.0% | Sep 26, 2019 | The Postmatic plugin before 1.4.6 for WordPress has XSS. |
| CVE-2015-9410 | MEDIUM | 5.4 | 1.2% | Sep 26, 2019 | The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now