icon

We found results for “

CVE-2015-9357

Good to know:

icon

Date: August 28, 2019

The akismet plugin before 3.1.5 for WordPress has XSS.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version pantheon-systems/wordpress-composer - 4.9.8;pantheon-systems/wordpress-composer - 5.0.1;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentynineteen/node-sass-7.0.0;pantheon-systems/wordpress-composer - 5.2;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/path-parse-1.0.7;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentynineteen/shell-quote-1.7.3;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/lodash-4.17.21;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/glob-parent-5.1.2;pantheon-systems/wordpress-composer - 5.1;pantheon-systems/wordpress-composer - dev-dependabot/npm_and_yarn/wp-content/themes/twentytwentyone/hosted-git-info-2.8.9;pantheon-systems/wordpress-composer - 5.2.2;ablypl/wordpress - v0.8.3;ablypl/wordpress - v0.9;ablypl/wordpress - v0.4.3;johnpbloch/wordpress-core - 4.2.0;johnpbloch/wordpress-core - 4.0.0;johnpbloch/wordpress-core - 4.4.0;johnpbloch/wordpress-core - 4.3.23;johnpbloch/wordpress-core - 4.3.0;johnpbloch/wordpress-core - 3.9.31;johnpbloch/wordpress-core - 4.3.26;johnpbloch/wordpress-core - 4.2.27;johnpbloch/wordpress-core - 4.2.30;johnpbloch/wordpress-core - 4.0.30;johnpbloch/wordpress-core - 3.9.34;johnpbloch/wordpress-core - 4.1.33;johnpbloch/wordpress-core - 4.1.30;johnpbloch/wordpress-core - 4.1.0;johnpbloch/wordpress-core - 4.0.33;wplib/wordpress - 1.5;wplib/wordpress - 4.4.beta1;humanit-se/wordpress-sv - v4.4.1;humanit-se/wordpress-sv - v4.1.25;humanit-se/wordpress-sv - v4.2.22;humanit-se/wordpress-sv - v4.3.18;zhangyingxi/zyxhome - no_fix;roots/wordpress-full - 4.3.34;roots/wordpress-full - 4.1.35;roots/wordpress-full - 4.0.35;roots/wordpress-full - 4.1.41;roots/wordpress-full - 4.2.38;themosis/themosis - 0.9.1;blair2004/themosis - 0.9.1;suh-neuger/nwt - 0.1.3;acosf/archersys - v2.5beta;acosf/archersys - 2.0.0;digitalmeat/themosis - 0.9.1;dcwiklik/wordpress - no_fix;webfatorial/wordpress - 3.8.2;webfatorial/wordpress - no_fix;laravel-plus/wordpress - v0.9;yott/wordpress - no_fix;ondrakub/wordpress-custom - no_fix;zynfly/themosis - 0.9.1;kinsta/kinsta-mu-plugins - no_fix;kinsta/kinsta-mu-plugins - 1.0.0;reginaldojunior/winners - v0.1.1-beta;ycms/framework - v5.1.0;gladeye/themosis - 0.9.1;ycms/wordpress - no_fix;poliondas/wordpress-br - no_fix;mvpdesign/themosis - 0.9.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us