2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-9433MEDIUM6.5The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration paramet...
CVE-2015-9432MEDIUM6.5The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/opt...
CVE-2015-9431MEDIUM6.5The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page...
CVE-2015-9449HIGH7.2The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=micro...
CVE-2015-9430MEDIUM6.1The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.
CVE-2015-9429MEDIUM6.5The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page...
CVE-2015-9428MEDIUM6.5The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-...
CVE-2015-9427MEDIUM6.5The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=...
CVE-2015-9426MEDIUM4.6The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?actio...
CVE-2015-9425MEDIUM5.4The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opan...
CVE-2015-9424MEDIUM6.5The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=mult...
CVE-2015-9423MEDIUM5.4The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields...
CVE-2015-9422MEDIUM6.5The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?...
CVE-2015-9421MEDIUM6.5The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?a...
CVE-2015-9420MEDIUM6.1The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_p...
CVE-2015-9419MEDIUM6.1The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section.
CVE-2015-9418MEDIUM4.3The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
CVE-2015-9417MEDIUM6.5The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
CVE-2015-9416MEDIUM6.1The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.
CVE-2015-9415HIGH7.5The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.
CVE-2015-9414MEDIUM6.1The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?...
CVE-2015-9413MEDIUM6.5The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-download...
CVE-2015-9412MEDIUM6.1The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.
CVE-2015-9411MEDIUM6.1The Postmatic plugin before 1.4.6 for WordPress has XSS.
CVE-2015-9410MEDIUM5.4The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now