2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18578The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.
CVE-2017-18586The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
CVE-2017-18584The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action.
CVE-2017-18583The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
CVE-2017-18582The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.
CVE-2017-18581The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.
CVE-2017-18580The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or use...
CVE-2017-18577The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
CVE-2017-18576The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.
CVE-2017-18575The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
CVE-2017-18574The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
CVE-2017-18573The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
CVE-2017-18572The gnucommerce plugin before 1.4.2 for WordPress has XSS.
CVE-2017-18571The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulner...
CVE-2017-18570The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download En...
CVE-2017-18562The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
CVE-2017-18561The embed-comment-images plugin before 0.6 for WordPress has XSS.
CVE-2017-18559MEDIUM6.1The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
CVE-2017-18535The smokesignal plugin before 1.2.7 for WordPress has XSS.
CVE-2017-18525The megamenu plugin before 2.4 for WordPress has XSS.
CVE-2017-18521The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage...
CVE-2017-18516The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.
CVE-2017-18564The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
CVE-2017-18563The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen.
CVE-2017-18565The updater plugin before 1.35 for WordPress has multiple XSS issues.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now