cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2015-3439,https://securityvulnerability.io/vulnerability/CVE-2015-3439,,"Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.",Wordpress,Debian Linux,,,0.009680000133812428,false,,false,false,false,,false,false,2015-08-05T10:00:00.000Z,0 CVE-2015-3440,https://securityvulnerability.io/vulnerability/CVE-2015-3440,,Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.,Wordpress,Debian Linux,,,0.6409900188446045,false,,false,false,false,,false,false,2015-08-03T14:00:00.000Z,0 CVE-2014-9039,https://securityvulnerability.io/vulnerability/CVE-2014-9039,,"wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.",Wordpress,Debian Linux,,,0.004809999838471413,false,,false,false,false,,false,false,2014-11-25T23:00:00.000Z,0 CVE-2014-5204,https://securityvulnerability.io/vulnerability/CVE-2014-5204,,"wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.",Wordpress,Debian Linux,,,0.0015200000489130616,false,,false,false,false,,false,false,2014-08-18T10:00:00.000Z,0