2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-9361The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9360The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9358The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9357The akismet plugin before 3.1.5 for WordPress has XSS.
CVE-2015-9356The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue ...
CVE-2015-9355The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.
CVE-2015-9352The wp-polls plugin before 2.72 for WordPress has SQL injection.
CVE-2015-9351The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more ...
CVE-2015-9350The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
CVE-2015-9348The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase I...
CVE-2015-9349The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
CVE-2015-9347The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
CVE-2015-9346The cp-polls plugin before 1.0.5 for WordPress has XSS.
CVE-2015-9345The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
CVE-2015-9344The link-log plugin before 2.1 for WordPress has SQL injection.
CVE-2015-9343The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
CVE-2015-9342The wp-rollback plugin before 1.2.3 for WordPress has XSS.
CVE-2015-9340The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4...
CVE-2015-9339The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
CVE-2015-9338The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
CVE-2015-9334The email-newsletter plugin through 20.15 for WordPress has SQL injection.
CVE-2015-9341The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
CVE-2015-9337The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJ...
CVE-2015-9336The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
CVE-2015-9335The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now