2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-9361——The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9360——The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9358——The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9357——The akismet plugin before 3.1.5 for WordPress has XSS.
CVE-2015-9356——The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue ...
CVE-2015-9355——The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.
CVE-2015-9352——The wp-polls plugin before 2.72 for WordPress has SQL injection.
CVE-2015-9351——The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more ...
CVE-2015-9350——The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
CVE-2015-9348——The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase I...
CVE-2015-9349——The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
CVE-2015-9347——The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
CVE-2015-9346——The cp-polls plugin before 1.0.5 for WordPress has XSS.
CVE-2015-9345——The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
CVE-2015-9344——The link-log plugin before 2.1 for WordPress has SQL injection.
CVE-2015-9343——The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
CVE-2015-9342——The wp-rollback plugin before 1.2.3 for WordPress has XSS.
CVE-2015-9340——The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4...
CVE-2015-9339——The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
CVE-2015-9338——The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
CVE-2015-9334——The email-newsletter plugin through 20.15 for WordPress has SQL injection.
CVE-2015-9341——The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
CVE-2015-9337——The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJ...
CVE-2015-9336——The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
CVE-2015-9335——The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now