2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-10992MEDIUM6.1The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from...
CVE-2016-10990MEDIUM6.1The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
CVE-2016-10988MEDIUM6.1The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, ...
CVE-2016-10987MEDIUM6.1The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
CVE-2016-10986MEDIUM6.1The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_...
CVE-2016-10985MEDIUM6.1The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
CVE-2016-10984MEDIUM6.1The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
CVE-2016-10983MEDIUM6.5The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of e...
CVE-2016-10981MEDIUM6.1The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_...
CVE-2016-10980MEDIUM6.1The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.
CVE-2016-10979MEDIUM6.1The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS.
CVE-2016-10977MEDIUM6.5The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.
CVE-2016-10976MEDIUM6.1The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.
CVE-2016-10975MEDIUM6.1The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter.
CVE-2016-10973MEDIUM6.1The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter...
CVE-2016-10970MEDIUM6.1The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.
CVE-2016-10969MEDIUM6.1The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title.
CVE-2016-10967MEDIUM6.1The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks....
CVE-2016-10964MEDIUM6.1The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
CVE-2016-10963MEDIUM6.1The icegram plugin before 1.9.19 for WordPress has XSS.
CVE-2016-10962MEDIUM6.5The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
CVE-2016-10961MEDIUM6.1The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.
CVE-2016-10959MEDIUM6.5The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_med...
CVE-2016-10957MEDIUM6.1The Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc paramet...
CVE-2016-10953MEDIUM5.4The Headway theme before 3.8.9 for WordPress has XSS via the license key field.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now