2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-10996MEDIUM5.3The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak...
CVE-2016-10994MEDIUM6.1The Truemag theme 2016 Q2 for WordPress has XSS via the s parameter.
CVE-2016-10993MEDIUM5.4The ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter.
CVE-2016-10992MEDIUM6.1The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from...
CVE-2016-10990MEDIUM6.1The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
CVE-2016-10988MEDIUM6.1The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, ...
CVE-2016-10987MEDIUM6.1The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
CVE-2016-10986MEDIUM6.1The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_...
CVE-2016-10985MEDIUM6.1The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
CVE-2016-10984MEDIUM6.1The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
CVE-2016-10983MEDIUM6.5The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of e...
CVE-2016-10981MEDIUM6.1The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_...
CVE-2016-10980MEDIUM6.1The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.
CVE-2016-10979MEDIUM6.1The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS.
CVE-2016-10977MEDIUM6.5The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.
CVE-2016-10976MEDIUM6.1The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.
CVE-2016-10975MEDIUM6.1The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter.
CVE-2016-10973MEDIUM6.1The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter...
CVE-2016-10970MEDIUM6.1The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.
CVE-2016-10969MEDIUM6.1The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title.
CVE-2016-10967MEDIUM6.1The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks....
CVE-2016-10964MEDIUM6.1The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
CVE-2016-10963MEDIUM6.1The icegram plugin before 1.9.19 for WordPress has XSS.
CVE-2016-10962MEDIUM6.5The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
CVE-2016-10961MEDIUM6.1The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now