2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9409 | MEDIUM | 6.5 | 1.1% | Sep 25, 2019 | The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php. |
| CVE-2015-9406 | HIGH | 7.5 | 55.0% | Sep 20, 2019 | Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary... |
| CVE-2015-9408 | MEDIUM | 6.5 | 1.1% | Sep 20, 2019 | The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS. |
| CVE-2015-9407 | MEDIUM | 6.1 | 1.6% | Sep 20, 2019 | The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS. |
| CVE-2015-9405 | MEDIUM | 6.1 | 1.5% | Sep 20, 2019 | The wp-piwik plugin before 1.0.5 for WordPress has XSS. |
| CVE-2015-9404 | MEDIUM | 6.1 | 1.3% | Sep 20, 2019 | The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS. |
| CVE-2015-9403 | MEDIUM | 6.1 | 1.2% | Sep 20, 2019 | The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS. |
| CVE-2015-9402 | HIGH | 8.8 | 2.0% | Sep 20, 2019 | The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. |
| CVE-2015-9401 | MEDIUM | 4.8 | 1.0% | Sep 20, 2019 | The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS. |
| CVE-2015-9400 | HIGH | 8.8 | 1.9% | Sep 20, 2019 | The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection. |
| CVE-2015-9399 | HIGH | 7.2 | 1.7% | Sep 20, 2019 | The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. |
| CVE-2015-9398 | HIGH | 8.8 | 1.9% | Sep 20, 2019 | The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection. |
| CVE-2015-9397 | MEDIUM | 5.4 | 1.0% | Sep 20, 2019 | The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS. |
| CVE-2015-9396 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file=... |
| CVE-2015-9395 | HIGH | 8.8 | 1.7% | Sep 20, 2019 | The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action. |
| CVE-2015-9394 | HIGH | 8.8 | 0.7% | Sep 20, 2019 | The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. |
| CVE-2015-9393 | MEDIUM | 5.4 | 0.7% | Sep 20, 2019 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. |
| CVE-2015-9392 | MEDIUM | 5.4 | 1.2% | Sep 20, 2019 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. |
| CVE-2015-9391 | MEDIUM | 6.1 | 1.3% | Sep 20, 2019 | The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter. |
| CVE-2015-9390 | MEDIUM | 4.3 | 0.9% | Sep 20, 2019 | The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are ... |
| CVE-2015-9389 | MEDIUM | 5.4 | 0.8% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name. |
| CVE-2015-9388 | MEDIUM | 6.5 | 0.7% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. |
| CVE-2015-9387 | MEDIUM | 6.5 | 0.7% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. |
| CVE-2015-9386 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation. |
| CVE-2015-9385 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | The quotes-and-tips plugin before 1.20 for WordPress has XSS. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now