We found results for “”
CVE-2015-9357
Good to know:
Date: August 28, 2019
The akismet plugin before 3.1.5 for WordPress has XSS.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version pantheon-systems/wordpress-composer - 4.9.8;pantheon-systems/wordpress-composer - 5.0.1;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentynineteen/node-sass-7.0.0;pantheon-systems/wordpress-composer - 5.2;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/path-parse-1.0.7;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentynineteen/shell-quote-1.7.3;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/lodash-4.17.21;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/glob-parent-5.1.2;pantheon-systems/wordpress-composer - 5.1;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/hosted-git-info-2.8.9;pantheon-systems/wordpress-composer - 5.2.2;ablypl/wordpress - v0.8.3;ablypl/wordpress - v0.9;ablypl/wordpress - v0.4.3;johnpbloch/wordpress-core - 4.2.0;johnpbloch/wordpress-core - 4.0.0;johnpbloch/wordpress-core - 4.4.0;johnpbloch/wordpress-core - 4.3.23;johnpbloch/wordpress-core - 4.3.0;johnpbloch/wordpress-core - 3.9.31;johnpbloch/wordpress-core - 4.3.26;johnpbloch/wordpress-core - 4.2.27;johnpbloch/wordpress-core - 4.2.30;johnpbloch/wordpress-core - 4.0.30;johnpbloch/wordpress-core - 3.9.34;johnpbloch/wordpress-core - 4.1.33;johnpbloch/wordpress-core - 4.1.30;johnpbloch/wordpress-core - 4.1.0;johnpbloch/wordpress-core - 4.0.33;wplib/wordpress - 1.5;wplib/wordpress - 4.4.beta1;humanit-se/wordpress-sv - v4.4.1;humanit-se/wordpress-sv - v4.1.25;humanit-se/wordpress-sv - v4.2.22;humanit-se/wordpress-sv - v4.3.18;zhangyingxi/zyxhome - no_fix;roots/wordpress-full - 4.3.34;roots/wordpress-full - 4.1.35;roots/wordpress-full - 4.0.35;roots/wordpress-full - 4.1.41;roots/wordpress-full - 4.2.38;themosis/themosis - 0.9.1;blair2004/themosis - 0.9.1;suh-neuger/nwt - 0.1.3;acosf/archersys - v2.5beta;acosf/archersys - 2.0.0;digitalmeat/themosis - 0.9.1;dcwiklik/wordpress - no_fix;webfatorial/wordpress - 3.8.2;webfatorial/wordpress - no_fix;laravel-plus/wordpress - v0.9;yott/wordpress - no_fix;ondrakub/wordpress-custom - no_fix;zynfly/themosis - 0.9.1;kinsta/kinsta-mu-plugins - no_fix;kinsta/kinsta-mu-plugins - 1.0.0;reginaldojunior/winners - v0.1.1-beta;ycms/framework - v5.1.0;gladeye/themosis - 0.9.1;ycms/wordpress - no_fix;poliondas/wordpress-br - no_fix;mvpdesign/themosis - 0.9.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | MEDIUM |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
| Additional information: |
Vulnerabilities
Projects
Contact Us


