2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10972CRITICAL9.8The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
CVE-2016-10971CRITICAL9.8The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an ...
CVE-2016-10970MEDIUM6.1The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.
CVE-2016-10969MEDIUM6.1The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title.
CVE-2016-10968HIGH8.8The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.
CVE-2016-10967MEDIUM6.1The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks....
CVE-2016-10966HIGH7.5The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
CVE-2016-10965HIGH7.5The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
CVE-2016-10964MEDIUM6.1The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
CVE-2016-10963MEDIUM6.1The icegram plugin before 1.9.19 for WordPress has XSS.
CVE-2016-10962MEDIUM6.5The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
CVE-2016-10961MEDIUM6.1The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.
CVE-2016-10960HIGH8.8The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php...
CVE-2016-10959MEDIUM6.5The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_med...
CVE-2016-10958HIGH7.5The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admi...
CVE-2016-10957MEDIUM6.1The Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc paramet...
CVE-2016-10956HIGH7.5The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.
CVE-2016-10955CRITICAL9.8The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
CVE-2016-10954CRITICAL9.8The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
CVE-2016-10953MEDIUM5.4The Headway theme before 3.8.9 for WordPress has XSS via the license key field.
CVE-2016-10952MEDIUM6.1The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page p...
CVE-2016-10951HIGH7.2The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
CVE-2016-10950HIGH8.8The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
CVE-2016-10949HIGH8.8The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
CVE-2016-10948HIGH8.1The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now