2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18578 | — | — | 0.9% | Aug 22, 2019 | The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS. |
| CVE-2017-18586 | — | — | 2.5% | Aug 22, 2019 | The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths. |
| CVE-2017-18584 | — | — | 1.4% | Aug 22, 2019 | The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action. |
| CVE-2017-18583 | — | — | 2.1% | Aug 22, 2019 | The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection. |
| CVE-2017-18582 | — | — | 0.9% | Aug 22, 2019 | The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues. |
| CVE-2017-18581 | — | — | 0.9% | Aug 22, 2019 | The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list. |
| CVE-2017-18580 | — | — | 12.1% | Aug 22, 2019 | The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or use... |
| CVE-2017-18577 | — | — | 0.9% | Aug 22, 2019 | The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg. |
| CVE-2017-18576 | — | — | 0.9% | Aug 22, 2019 | The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation. |
| CVE-2017-18575 | — | — | 0.9% | Aug 22, 2019 | The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues. |
| CVE-2017-18574 | — | — | 0.9% | Aug 22, 2019 | The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder. |
| CVE-2017-18573 | — | — | 1.8% | Aug 22, 2019 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. |
| CVE-2017-18572 | — | — | 0.9% | Aug 22, 2019 | The gnucommerce plugin before 1.4.2 for WordPress has XSS. |
| CVE-2017-18571 | — | — | 1.8% | Aug 22, 2019 | The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulner... |
| CVE-2017-18570 | — | — | 1.8% | Aug 22, 2019 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download En... |
| CVE-2017-18562 | — | — | 1.4% | Aug 21, 2019 | The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues. |
| CVE-2017-18561 | — | — | 0.9% | Aug 21, 2019 | The embed-comment-images plugin before 0.6 for WordPress has XSS. |
| CVE-2017-18559 | MEDIUM | 6.1 | 0.9% | Aug 21, 2019 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. |
| CVE-2017-18535 | — | — | 0.9% | Aug 21, 2019 | The smokesignal plugin before 1.2.7 for WordPress has XSS. |
| CVE-2017-18525 | — | — | 0.9% | Aug 21, 2019 | The megamenu plugin before 2.4 for WordPress has XSS. |
| CVE-2017-18521 | — | — | 0.7% | Aug 21, 2019 | The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage... |
| CVE-2017-18516 | — | — | 1.7% | Aug 21, 2019 | The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues. |
| CVE-2017-18564 | — | — | 1.4% | Aug 21, 2019 | The sender plugin before 1.2.1 for WordPress has multiple XSS issues. |
| CVE-2017-18563 | — | — | 0.9% | Aug 21, 2019 | The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen. |
| CVE-2017-18565 | — | — | 1.4% | Aug 21, 2019 | The updater plugin before 1.35 for WordPress has multiple XSS issues. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now