CVE-2019-10058
Various Lexmark products have Incorrect Access Control.
Source: CVE-2019-10058
CVE-2015-9359
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9359
CVE-2019-15716
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.
Source: CVE-2019-15716
CVE-2015-9379
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9379
CVE-2015-9378
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9378
CVE-2015-9374
Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9374
CVE-2015-9377
iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9377
CVE-2015-9372
Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9372
CVE-2015-9376
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9376
CVE-2015-9375
Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9375