NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26661 | CVE-2015-5528 | Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 26660 | CVE-2015-5523 | The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26659 | CVE-2015-5522 | Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26658 | CVE-2015-5521 | Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-14 | View | |
| 26657 | CVE-2015-5520 | Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-17 | View |
Page 3022 of 17672, showing 5 records out of 88360 total, starting on record 15106, ending on 15110