2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-9335The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
CVE-2015-9333CRITICAL9.8The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
CVE-2015-9328The profile-builder plugin before 2.2.5 for WordPress has XSS.
CVE-2015-9327The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
CVE-2015-9321The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
CVE-2015-9320MEDIUM6.1The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
CVE-2015-9319The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
CVE-2015-9332The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=unins...
CVE-2015-9331The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
CVE-2015-9330The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
CVE-2015-9329The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
CVE-2015-9318The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
CVE-2015-9317The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
CVE-2015-9324CRITICAL9.8The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
CVE-2015-9323CRITICAL9.8The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
CVE-2015-9322The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
CVE-2015-9326The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
CVE-2015-9325The visitors-online plugin before 0.4 for WordPress has SQL injection.
CVE-2015-9310The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
CVE-2015-9309HIGH8.8The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
CVE-2015-9308HIGH8.8The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
CVE-2015-9307HIGH8.8The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
CVE-2015-9316The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppoll...
CVE-2015-9315The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
CVE-2015-9314The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now