• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-9646

February 26, 2023 by

The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the “custom edition area.”

CVE-2019-9647

February 26, 2023 by

Gila CMS 1.9.1 has XSS.

CVE-2019-9650

February 26, 2023 by

An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.

CVE-2019-9660

February 26, 2023 by

Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html “catname” parameter.

CVE-2019-9661

February 26, 2023 by

Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html “value” parameter,

CVE-2019-9669

February 26, 2023 by

** DISPUTED ** The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is not a valid vulnerability in the context of the Wordfence WordPress plugin as the firewall rules are not maintained as part of the Wordfence software but rather it is a set of rules hosted on vendor servers and pushed to the plugin with no versioning associated. Bypassing a WAF rule doesn’t make a WordPress site vulnerable (speaking in terms of software vulnerabilities).

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 957
  • Go to page 958
  • Go to page 959
  • Go to page 960
  • Go to page 961
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE