2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10923The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
CVE-2016-10922The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
CVE-2016-10921The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVE-2016-10920The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
CVE-2016-10919The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di...
CVE-2016-10918The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
CVE-2016-10917The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different v...
CVE-2016-10916The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV...
CVE-2016-10891The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
CVE-2016-10890The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
CVE-2016-10912The universal-analytics plugin before 1.3.1 for WordPress has XSS.
CVE-2016-10911The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
CVE-2016-10910The formbuilder plugin before 1.06 for WordPress has multiple XSS issues.
CVE-2016-10909The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
CVE-2016-10908The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
CVE-2016-10903The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
CVE-2016-10902The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
CVE-2016-10901The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
CVE-2016-10900The uji-countdown plugin before 2.0.7 for WordPress has XSS.
CVE-2016-10899The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
CVE-2016-10898The total-security plugin before 3.4.1 for WordPress has XSS.
CVE-2016-10897The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
CVE-2016-10896The seo-redirection plugin before 4.3 for WordPress has stored XSS.
CVE-2016-10895The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
CVE-2016-10892The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now