NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25597 | CVE-2015-4063 | Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php. | 2 | 3.5 | Low | 2017-01-19 | 2015-05-28 | View | |
| 27428 | CVE-2015-6535 | Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter). | 2 | 3.5 | Low | 2017-01-19 | 2016-12-21 | View | |
| 42126 | CVE-2013-7419 | Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2015-01-12 | View | |
| 61306 | CVE-2006-2611 | Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in the variable handler in MediaWiki 1.6.x before r14349 allows remote attackers to inject arbitrary Javascript via unspecified vectors, possibly involving the usage of the | (pipe) character. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 55150 | CVE-2007-2991 | Cross-site scripting (XSS) vulnerability in includes/send.inc.php in Evenzia CMS allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | 2 | 4.3 | Medium | 2017-01-07 | 2012-10-30 | View |
Page 3308 of 17672, showing 5 records out of 88360 total, starting on record 16536, ending on 16540