Vulnerabilities protected by our XSS: Cross Site Scripting firewall rule

33,803,135
Attacks Blocked in Past 24 Hours

Showing 6061-6080 of 6,219 Vulnerabilities

Title CVE ID CVSS Vector Date
Adminer < 1.4.4 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N March 4, 2016
User Submitted Posts < 20160215 - Reflected Cross-Site Scripting CVE-2016-11001 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N February 10, 2016
Appointment Booking Calendar <= 1.2.24 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N January 26, 2016
Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N December 8, 2015
Toolset Types < 1.8.8 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N November 10, 2015
Jetpack <= 3.7.1 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N October 1, 2015
Crazy Bone < 0.6.0 - Stored Cross-Site Scripting CVE-2015-9430 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N August 21, 2015
Social Media Widget by Acurax < 2.2 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N August 19, 2015
WP-Polls <= 2.70 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N August 14, 2015
WP-CopyProtect [Protect your blog posts] <= 3.0.0 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N June 30, 2015
NewStatPress <= 1.0.3 - Stored Cross-Site Scripting CVE-2015-9314 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N June 30, 2015
NextScripts: Social Networks Auto-Poster <= 3.4.17 - Stored Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N May 25, 2015
Free counter <= 1.1 - Stored Cross-Site Scripting CVE-2015-4084 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N May 25, 2015
Roomcloud < 1.3 - Cross-Site Scripting CVE-2015-3904 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N May 9, 2015
WordPress Core < 4.2.2 - Cross-Site Scripting via Comments CVE-2015-8834 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N May 7, 2015
Jetpack <= 3.5.2 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N May 6, 2015
WordPress Core < 4.2.1 - Cross-Site Scripting via Comments CVE-2015-3440 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N April 27, 2015
WordPress Core < 4.1.2 - Cross-Site Scripting CVE-2015-3438 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N April 21, 2015
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) <= 5.3.3 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N April 20, 2015
WPtouch <= 3.7.5.3 - Cross-Site Scripting 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N April 20, 2015

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation