plugin

Akismet Vulnerabilities

2 known security issues reported for the Akismet WordPress plugin. Most recent disclosed Oct 13, 2015.

2 medium

Running Akismet on your site? Check whether your installed version is affected.

Scan your site free

Akismet <= 3.1.4 - Cross-Site Scripting

medium

The akismet plugin before 3.1.5 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Oct 13, 2015

CVE-2015-9357 on NVD →

Akismet Spam Protection < 2.0.2 - Cross-Site Scripting

medium

The Akismet Spam Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _wp_http_referer’ parameter in versions before 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever...

CVSS:
6.1
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
May 14, 2007

CVE-2007-2714 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database