2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-18544The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
CVE-2017-18543The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
CVE-2017-18542The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
CVE-2017-18541The xo-security plugin before 1.5.3 for WordPress has XSS.
CVE-2017-18548The note-press plugin before 0.1.2 for WordPress has SQL injection.
CVE-2017-14232The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a deni...
CVE-2017-18513The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
CVE-2017-18512The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
CVE-2017-18511The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
CVE-2017-18510The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio...
CVE-2017-18515The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
CVE-2017-18488The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues.
CVE-2017-18487The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
CVE-2017-18507The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
CVE-2017-18498The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.
CVE-2017-18497The liveforms plugin before 3.4.0 for WordPress has XSS.
CVE-2017-18496The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
CVE-2017-18495The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
CVE-2017-18494The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.
CVE-2017-18493The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.
CVE-2017-18492The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
CVE-2017-18491The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
CVE-2017-18490The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
CVE-2017-18489The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
CVE-2017-18505The twitter-plugin plugin before 2.55 for WordPress has XSS.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now