2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-9328——The profile-builder plugin before 2.2.5 for WordPress has XSS.
CVE-2015-9327——The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
CVE-2015-9321——The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
CVE-2015-9319——The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
CVE-2015-9332——The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=unins...
CVE-2015-9331——The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
CVE-2015-9330——The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
CVE-2015-9329——The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
CVE-2015-9318——The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
CVE-2015-9317——The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
CVE-2015-9322——The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
CVE-2015-9326——The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
CVE-2015-9325——The visitors-online plugin before 0.4 for WordPress has SQL injection.
CVE-2015-9310——The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
CVE-2015-9316——The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppoll...
CVE-2015-9315——The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
CVE-2015-9314——The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
CVE-2015-9313——The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
CVE-2015-9312——The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
CVE-2015-9311——The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
CVE-2015-9301——The liveforms plugin before 3.2.0 for WordPress has SQL injection.
CVE-2015-9300——The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
CVE-2015-9299——The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
CVE-2015-9296——The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
CVE-2015-9295——The contact-form-plugin plugin before 3.96 for WordPress has XSS.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now