CVE-2015-10000 to CVE-2015-10999
16 CVEs with public proof-of-concept exploits.
- CVE-2015-100011 PoCWP-Stats < 2.5.2 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2015-100341 PoCj-nowak workout-organizer sql injection
- CVE-2015-100731 PoCtinymighty WikiSEO Meta Property Tag WikiSEO.body.php modifyHTML cross site scripting
- CVE-2015-100872 PoCsUpThemes Theme DesignFolio Plus unrestricted upload
- CVE-2015-101332 PoCsSubscribe to Comments <= 2.1.2 - Local File Includion
- CVE-2015-101341 PoCSimple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
- CVE-2015-101352 PoCsWPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload
- CVE-2015-101361 PoCGI-Media Library < 3.0 - Directory Traversal
- CVE-2015-101372 PoCsWebsite Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
- CVE-2015-101382 PoCsWork The Flow File Upload <= 2.5.2 - Arbitrary File Upload
- CVE-2015-101391 PoCWPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation
- CVE-2015-101402 PoCsAjax Load More < 2.8.1.2 - Subscriber+ File Upload & Deletion
- CVE-2015-101416 PoCsXdebug Remote Debugger Unauthenticated OS Command Execution
- CVE-2015-101431 PoCPlatform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update
- CVE-2015-101442 PoCsResponsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2015-101451 PoCGargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh