2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-9465HIGH8.8The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via...
CVE-2015-9463HIGH7.5The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/u...
CVE-2015-9464HIGH7.5The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets...
CVE-2015-9462HIGH7.2The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat...
CVE-2015-9461HIGH7.2The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via t...
CVE-2015-9460HIGH8.8The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language ...
CVE-2015-9458HIGH7.2The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms coun...
CVE-2015-9457HIGH7.2The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parame...
CVE-2015-9455HIGH8.1The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-ad...
CVE-2015-9454HIGH8.8The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin ...
CVE-2015-9448HIGH8.8The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid paramete...
CVE-2015-9446HIGH8.8The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
CVE-2015-9445HIGH8.8The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unite...
CVE-2015-9449HIGH7.2The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=micro...
CVE-2015-9415HIGH7.5The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.
CVE-2015-9406HIGH7.5Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary...
CVE-2015-9402HIGH8.8The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
CVE-2015-9400HIGH8.8The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.
CVE-2015-9399HIGH7.2The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.
CVE-2015-9398HIGH8.8The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.
CVE-2015-9395HIGH8.8The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.
CVE-2015-9394HIGH8.8The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
CVE-2015-9353HIGH7.2The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-...
CVE-2015-9309HIGH8.8The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
CVE-2015-9308HIGH8.8The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now