{"id":"CVE-2017-15867","details":"Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parameter to admin/partials/listing/listing.php.","modified":"2026-07-08T05:51:28.493448836Z","published":"2017-10-24T19:29:00.197Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:user-login-history_project:user-login-history:*:*:*:*:*:wordpress:*:*"],"extracted_events":[{"last_affected":"1.5.2"}],"source":"CPE_RANGE","vendor_product":"user-login-history_project:user-login-history"},{"extracted_events":[{"fixed":"1.5.2"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://wpvulndb.com/vulnerabilities/8939"},{"type":"FIX","url":"https://github.com/faiyazalam/WordPress-plugin-user-login-history/commit/519341a7dece59e2c589b908a636e6cf12a61741"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/faiyazalam/wordpress-plugin-user-login-history","events":[{"introduced":"0"},{"fixed":"519341a7dece59e2c589b908a636e6cf12a61741"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15867.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}