CVE-2016-1000140: Reflected XSS in wordpress plugin new-year-firework v1.1.9
Reflected XSS in wordpress plugin new-year-firework v1.1.9
Published Oct 10, 2016 · Updated Aug 6, 2024
Browse CVE records published in October 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 706 matching CVEs · Page 5 of 15.
Reflected XSS in wordpress plugin new-year-firework v1.1.9
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin simpel-reserveren v3.5.2
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin hdw-tube v1.2
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin whizz v1.0.7
Published Oct 10, 2016 · Updated Aug 6, 2024
Ruckus Wireless H500 web management interface denial of service
Published Oct 25, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin tera-charts v1.0
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin hero-maps-pro v2.1.0
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin indexisto v1.0.5
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin heat-trackr v1.0
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin s3-video v0.983
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin simplified-content v1.0.0
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin e-search v1.0
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin photoxhibit v2.1.8
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin infusionsoft v1.5.11
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin hdw-tube v1.2
Published Oct 10, 2016 · Updated Aug 6, 2024
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
Published Oct 6, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin e-search v1.0
Published Oct 10, 2016 · Updated Aug 6, 2024
Zotpress plugin for WordPress SQLi in zp_get_account()
Published Oct 6, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin forget-about-shortcode-buttons v1.1.1
Published Oct 10, 2016 · Updated Aug 6, 2024
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
Published Oct 6, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin pondol-carousel v1.0
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin parsi-font v4.2.5
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin anti-plagiarism v3.60
Published Oct 10, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin page-layout-builder v1.9.3
Published Oct 10, 2016 · Updated Aug 6, 2024
XSS & SQLi in HugeIT slideshow v1.0.4
Published Oct 21, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin admin-font-editor v1.8
Published Oct 10, 2016 · Updated Aug 6, 2024
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
Published Oct 27, 2016 · Updated Aug 6, 2024
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
Published Oct 6, 2016 · Updated Aug 6, 2024
Reflected XSS in wordpress plugin defa-online-image-protector v3.3
Published Oct 10, 2016 · Updated Aug 6, 2024
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
Published Oct 6, 2016 · Updated Aug 6, 2024
XSS & SQLi in HugeIT slideshow v1.0.4
Published Oct 21, 2016 · Updated Aug 6, 2024
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
Published Oct 27, 2016 · Updated Aug 6, 2024
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
Published Oct 27, 2016 · Updated Aug 6, 2024
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
Published Oct 6, 2016 · Updated Aug 6, 2024
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
Published Oct 21, 2016 · Updated Aug 6, 2024
XSS in huge IT gallery v1.1.5 for Joomla
Published Oct 6, 2016 · Updated Aug 6, 2024
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
Published Oct 21, 2016 · Updated Aug 6, 2024
Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code.
Published Oct 7, 2016 · Updated Aug 6, 2024
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.
Published Oct 25, 2016 · Updated Aug 6, 2024
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
Published Oct 6, 2016 · Updated Aug 6, 2024
Pagure 2.2.1 XSS in raw file endpoint
Published Oct 7, 2016 · Updated Aug 6, 2024
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Published Oct 25, 2016 · Updated Aug 6, 2024
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
Published Oct 25, 2016 · Updated Aug 6, 2024
flask-oidc version 0.1.2 and earlier is vulnerable to an open redirect
Published Oct 7, 2016 · Updated Aug 6, 2024
TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the devices.
Published Oct 6, 2016 · Updated Aug 6, 2024
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
Published Oct 16, 2019 · Updated Aug 6, 2024
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
Published Oct 16, 2019 · Updated Aug 6, 2024
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
Published Oct 16, 2019 · Updated Aug 6, 2024