Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2016-10992
The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.
Music Store
after 1.0.141
HIGH 7.5
CVE-2015-9348
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
Sell Downloads
1.0.8+
MEDIUM 6.1
CVE-2014-10395
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
Polls Cp
1.0.1+
MEDIUM 6.1
CVE-2015-9346
The cp-polls plugin before 1.0.5 for WordPress has XSS.
Polls Cp
1.0.5+
CRITICAL 9.8
CVE-2016-10916
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
Appointment Booking Calendar
1.1.24+
CRITICAL 9.8
CVE-2016-10909
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
Booking Calendar Contact Form
1.0.24+
MEDIUM 6.1
CVE-2016-10908
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
Booking Calendar Contact Form
1.0.24+
MEDIUM 6.1
CVE-2019-14784
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
Cp Contact Form With Paypal
1.2.98+
HIGH 8.8
CVE-2018-20964
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
Contact Form Email
1.2.66+
MEDIUM 6.1
CVE-2018-20963
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
Contact Form Email
1.2.66+
MEDIUM 6.1
CVE-2019-14791
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
Appointment Booking Calendar
No fix yet
MEDIUM 5.4
CVE-2019-14785
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form…
Cp Contact Form With Paypal
1.2.99+
MEDIUM 6.1
CVE-2019-9646
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom …
Contact Form Email
1.2.66+
MEDIUM 6.1
CVE-2015-7666
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_messag…
Payment Form For Paypal Pro
after 1.0.1
HIGH 8.8
CVE-2015-9233
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contac…
Cp Contact Form With Paypal
1.1.6+
HIGH 7.5
CVE-2015-7319
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPre…
Appointment Booking Calendar
after 1.1.7