CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.
do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
The BackpackCRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
