VendorsNewStatPress Projectnewstatpressall versions
Vulnerabilities

NewStatPress Project NewStatPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2015-9313
The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
Published 2019-08-14 · Modified
9.8EPSS 0.018
CVE-2015-9315
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
Published 2019-08-14 · Modified
9.8EPSS 0.018
CVE-2015-4062
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.
Published 2015-05-27 · Modified
6.51 PoCEPSS 0.091
CVE-2015-9312
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
Published 2019-08-14 · Modified
6.1EPSS 0.018
CVE-2022-0206
NewStatPress < 1.3.6 - Reflected Cross-Site Scripting
Published 2022-02-14 · Modified
6.1EPSS 0.015
CVE-2015-9311
The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
Published 2019-08-14 · Modified
6.1EPSS 0.009
CVE-2015-9314
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
Published 2019-08-14 · Modified
6.1EPSS 0.009
CVE-2017-18575
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2017-20094
NewStatPress Plugin Persistent cross site scriting
Published 2022-06-24 · Modified
5.4EPSS 0.006
CVE-2015-4063
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.
Published 2015-05-27 · Modified
3.51 PoCEPSS 0.061