Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.5 vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2016-10939
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
Xtremelocator Xtremelocator 1.5
6.5
CVSSv2
CVE-2015-9475
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
Pont Project Pont 1.5
6.5
CVSSv2
CVE-2017-9603
SQL injection vulnerability in the WP Jobs plugin prior to 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.
Intensewp Wp Jobs
1 EDB exploit
5
CVSSv2
CVE-2017-1002006
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
Dtracker Project Dtracker 1.5
5
CVSSv2
CVE-2017-1002007
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
Dtracker Project Dtracker 1.5
5
CVSSv2
CVE-2017-1002004
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
Dtracker Project Dtracker 1.5
5
CVSSv2
CVE-2017-1002005
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.
Dtracker Project Dtracker 1.5
4.3
CVSSv2
CVE-2014-1888
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin prior to 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by le...
Buddypress Buddypress
Buddypress Buddypress 1.5
Buddypress Buddypress 1.5.1
Buddypress Buddypress 1.5.2
Buddypress Buddypress 1.5.3
Buddypress Buddypress 1.5.3.1
Buddypress Buddypress 1.5.4
Buddypress Buddypress 1.5.5
Buddypress Buddypress 1.5.6
Buddypress Buddypress 1.5.7
Buddypress Buddypress 1.6
Buddypress Buddypress 1.6.1
Buddypress Buddypress 1.6.2
Buddypress Buddypress 1.6.3
Buddypress Buddypress 1.6.4
Buddypress Buddypress 1.6.5
Buddypress Buddypress 1.7
Buddypress Buddypress 1.7.1
Buddypress Buddypress 1.7.2
Buddypress Buddypress 1.7.3
Buddypress Buddypress 1.8
Buddypress Buddypress 1.8.1
3.5
CVSSv2
CVE-2018-10309
The Responsive Cookie Consent plugin prior to 1.8 for WordPress mishandles number fields, leading to XSS.
Responsive Cookie Consent Project Responsive Cookie Consent
1 EDB exploit
7.5
CVSSv2
CVE-2012-6625
SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin prior to 1.7.4 for WordPress allows remote malicious users to execute arbitrary SQL commands via the groupid parameter in an editgroup action.
Vasthtml Forumpress 1.5.1
Vasthtml Forumpress 1.6.2
Vasthtml Forumpress 1.6.9
Vasthtml Forumpress 1.3
Vasthtml Forumpress 1.6.8
Vasthtml Forumpress 1.7.1
Vasthtml Forumpress 1.6.5
Vasthtml Forumpress 1.0
Vasthtml Forumpress 1.6.3
Vasthtml Forumpress 1.7
Vasthtml Forumpress 1.5
Vasthtml Forumpress 1.4
Vasthtml Forumpress 1.5.2
Vasthtml Forumpress 1.6.6
Vasthtml Forumpress 1.2
Vasthtml Forumpress 1.1
Vasthtml Forumpress 1.6.7
Vasthtml Forumpress 1.7.3
Vasthtml Forumpress 1.6
Vasthtml Forumpress 1.7.2
Vasthtml Forumpress
Vasthtml Forumpress 1.6.4
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »