Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2015-9503 Cross-site Scripting vulnerability in Webmandesign Modern Theme
The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier.
4.3
2019-10-23 CVE-2015-9502 Cross-site Scripting vulnerability in Webmandesign Auberge Theme
The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier.
4.3
2019-10-23 CVE-2019-16975 Cross-site Scripting vulnerability in Fusionpbx
In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
network
fusionpbx CWE-79
4.3
2019-10-23 CVE-2015-9536 Cross-site Scripting vulnerability in multiple products
The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
4.3
2019-10-23 CVE-2015-9535 Cross-site Scripting vulnerability in multiple products
The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
4.3
2019-10-23 CVE-2015-9534 Cross-site Scripting vulnerability in multiple products
The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
4.3
2019-10-23 CVE-2015-9533 Cross-site Scripting vulnerability in multiple products
The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
4.3
2019-10-23 CVE-2015-9532 Cross-site Scripting vulnerability in multiple products
The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
4.3
2019-10-23 CVE-2015-9531 Cross-site Scripting vulnerability in multiple products
The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
4.3
2019-10-23 CVE-2015-9530 Cross-site Scripting vulnerability in multiple products
The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
4.3