2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9424 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=mult... |
| CVE-2015-9423 | MEDIUM | 5.4 | 1.0% | Sep 26, 2019 | The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields... |
| CVE-2015-9422 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?... |
| CVE-2015-9421 | MEDIUM | 6.5 | 0.9% | Sep 26, 2019 | The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?a... |
| CVE-2015-9420 | MEDIUM | 6.1 | 1.4% | Sep 26, 2019 | The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_p... |
| CVE-2015-9419 | MEDIUM | 6.1 | 1.2% | Sep 26, 2019 | The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section. |
| CVE-2015-9418 | MEDIUM | 4.3 | 0.6% | Sep 26, 2019 | The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes. |
| CVE-2015-9417 | MEDIUM | 6.5 | 0.7% | Sep 26, 2019 | The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS. |
| CVE-2015-9416 | MEDIUM | 6.1 | 1.0% | Sep 26, 2019 | The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header. |
| CVE-2015-9414 | MEDIUM | 6.1 | 3.6% | Sep 26, 2019 | The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?... |
| CVE-2015-9413 | MEDIUM | 6.5 | 1.1% | Sep 26, 2019 | The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-download... |
| CVE-2015-9412 | MEDIUM | 6.1 | 1.2% | Sep 26, 2019 | The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter. |
| CVE-2015-9411 | MEDIUM | 6.1 | 1.0% | Sep 26, 2019 | The Postmatic plugin before 1.4.6 for WordPress has XSS. |
| CVE-2015-9410 | MEDIUM | 5.4 | 1.2% | Sep 26, 2019 | The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter. |
| CVE-2015-9409 | MEDIUM | 6.5 | 1.1% | Sep 25, 2019 | The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php. |
| CVE-2015-9408 | MEDIUM | 6.5 | 1.1% | Sep 20, 2019 | The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS. |
| CVE-2015-9407 | MEDIUM | 6.1 | 1.6% | Sep 20, 2019 | The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS. |
| CVE-2015-9405 | MEDIUM | 6.1 | 1.5% | Sep 20, 2019 | The wp-piwik plugin before 1.0.5 for WordPress has XSS. |
| CVE-2015-9404 | MEDIUM | 6.1 | 1.3% | Sep 20, 2019 | The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS. |
| CVE-2015-9403 | MEDIUM | 6.1 | 1.2% | Sep 20, 2019 | The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS. |
| CVE-2015-9401 | MEDIUM | 4.8 | 1.0% | Sep 20, 2019 | The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS. |
| CVE-2015-9397 | MEDIUM | 5.4 | 1.0% | Sep 20, 2019 | The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS. |
| CVE-2015-9396 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file=... |
| CVE-2015-9393 | MEDIUM | 5.4 | 0.7% | Sep 20, 2019 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. |
| CVE-2015-9392 | MEDIUM | 5.4 | 1.2% | Sep 20, 2019 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now