Vulnerabilities (CVE)

Filtered by CWE-79
Total 47280 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9514 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Free Downloads 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9513 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Favorites 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9512 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Csv Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) CSV Manager extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9511 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Conditional Success Redirects 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Conditional Success Redirects extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9510 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Cross-sell And Upsell 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Cross-sell Upsell extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9509 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Content Restriction 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9508 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Commissions 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9507 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Attach Accounts To Orders 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9506 2 Awesomemotive, Easydigitaldownloads 2 Easy Digital Downloads, Amazon S3 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
CVE-2015-9505 1 Awesomemotive 1 Easy Digital Downloads 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.
CVE-2015-9504 1 Weeklynews Theme Project 1 Weeklynews Theme 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.
CVE-2015-9503 1 Webmandesign 1 Modern Theme 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2015-9502 1 Webmandesign 1 Auberge Theme 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2015-9501 1 Artificial Intelligence Project 1 Artificial Intelligence 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.
CVE-2015-9500 1 Exquisite Ultimate Newspaper Project 1 Exquisite Ultimate Newspaper 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
CVE-2015-9495 1 Syndication Links Project 1 Syndication Links 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2015-9494 1 Indieweb Post Kinds Project 1 Indieweb Post Kinds 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2015-9493 1 Nlb-creationst 1 My Wish List 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.
CVE-2015-9478 1 No-margin-for-error 1 Prettyphoto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.
CVE-2015-9472 1 Monitorbacklinks 1 Incoming Links 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.