cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2015-9391,https://securityvulnerability.io/vulnerability/CVE-2015-9391,,The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.,Wordpress,YaWPp,6.1,MEDIUM,0.0006600000197067857,false,,false,false,false,,false,false,2019-09-20T14:59:52.000Z,0 CVE-2014-5182,https://securityvulnerability.io/vulnerability/CVE-2014-5182,,"Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin.php.",Wordpress,YaWPp,,,0.00171999994199723,false,,false,false,false,,false,false,2014-08-06T19:55:00.000Z,0