vciy

CVEs we hold for John

Records whose assigning authority named John as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9109GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translation Storagejohn-dagelmore GPTranslate – Multilingual AI Translation…
CVE-2026-89278GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Scriptjohn-dagelmore GPTranslate – Multilingual AI Translation…
CVE-2026-84765WordPress Breadcrumb NavXT plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerabilityJohn Havlik Breadcrumb NavXT
CVE-2026-81806WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerabilityJohn Darrel Hide My WP Ghost
CVE-2026-7527WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 'redirect_to' Parameterjohndarrel Hide My WP Ghost – Security & Firewall
CVE-2026-74010WordPress bbPress plugin <= 2.6.14 - Broken Access Control vulnerabilityJohn James Jacoby bbPress
CVE-2026-65490WordPress Create by Mediavine plugin <= 2.6.0 - Sensitive Data Exposure vulnerabilityJohn-Michael L'Allier Create
CVE-2026-64896T2000 open debug portJohnson Controls T2000
CVE-2026-64887Airwall - Hardcoded SecretsJohnson Controls Airwall
CVE-2026-62137WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerabilityJohn James Jacoby bbPress
CVE-2026-59546WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerabilityJohn Darrel Hide My WP Ghost
CVE-2026-57913no title heldJohnson Audit Tracking Management System
CVE-2026-57912no title heldJohnson Campus Recruiting
CVE-2026-4267Query Monitor <= 3.20.3 - Reflected Cross-Site Scripting via Request URIjohnbillion Query Monitor
CVE-2026-4089Twittee Text Tweet <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attributejohnnie2u Twittee Text Tweet
CVE-2026-39484WordPress Hide My WP Ghost plugin < 7.0.00 - Open Redirection vulnerabilityJohn Darrel Hide My WP Ghost
CVE-2026-34497FMS Employee Vulnerable to HTML InjectionJohnson Controls FM Systems Employee
CVE-2026-34496victor Web - Priviledge EscalationJohnson Controls victor Web
CVE-2026-34495FMS Employee vulnerable to XSSJohnson Controls FM Systems Employee
CVE-2026-34492Airwall - Arbitrary file readJohnson Controls Airwall
CVE-2026-34491no title heldJohnson Controls Metasys 15
CVE-2026-34490XAAP Android Data Stored in Unencrypted DatabaseJohnson Controls XAAP Application
CVE-2026-27875Simplex Incident Manager Clear TestJohnson Controls Simplex Incident Manager / Autocall Fire…
CVE-2026-27871TL280Johnson Controls TL280
CVE-2026-24552WordPress Create plugin <= 2.5.3 - SQL Injection vulnerabilityJohn-Michael L'Allier Create
CVE-2026-24542WordPress WP Term Order plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) vulnerabilityJohn James Jacoby WP Term Order
CVE-2026-21662FMS Employee Allows Upload of Unrestricted FilesJohnson Controls FM Systems Employee
CVE-2026-21661AC2000 Uncontrolled Search Path ElementJohnson Controls AC2000
CVE-2026-21660Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in FirmwareJohnson Controls Frick Controls Quantum HD
CVE-2026-21659Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File…Johnson Controls Frick Controls Quantum HD
CVE-2026-21658Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21657Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21656Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21655C-CURE 9000 and Victor application server - Deserialization of Untrusted DataJohnson Controls Victor Application Server
CVE-2026-21654Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21653CCure and Victor Application Server - Server Side Request ForgeryJohnson Controls CCure 9000 and victor application server
CVE-2026-1877Auto Post Scheduler <= 1.84 - Cross-Site Request Forgery to Stored Cross-Site Scripting via aps_options_pagejohnh10 Auto Post Scheduler
CVE-2026-10692johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redosjohnhuang316 code-index-mcp
CVE-2025-8678WP Crontrol - 1.17.0 - 1.19.1 - Authenticated (Administrator+) Blind Server-Side Request Forgeryjohnbillion WP Crontrol
CVE-2025-62937WordPress Post List Featured Image plugin <= 0.5.9 - Cross Site Scripting (XSS) vulnerabilityJohnny Post List Featured Image
CVE-2025-61740Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation ErrorJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
CVE-2025-61739Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryptionJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
CVE-2025-61738Johnson Controls PowerG and IQPanel cleartext transmission of sensitive informationJohnson Controls IQPanel2, IQHub,IQPanel2+,IQPanel 4,PowerG
CVE-2025-61736iSTAR- Improper Validation of Certificate ExpirationJohnson Controls iSTAReX, iSTAR Edge, iSTAR Ultra LT, iSTAR…
CVE-2025-60134WordPress WP Media Categories Plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) VulnerabilityJohn James Jacoby WP Media Categories
CVE-2025-60132WordPress Video Blogster Lite Plugin <= 1.2 - Cross Site Request Forgery (CSRF) Vulnerabilityjohnh10 Video Blogster Lite
CVE-2025-58841WordPress Media Author Plugin <= 1.0.4 - Broken Access Control VulnerabilityJohn Luetke Media Author
CVE-2025-53696no title heldJohnson Controls, Inc iSTAR Ultra
CVE-2025-53695no title heldJohnson Controls, Inc iSTAR Ultra
CVE-2025-52809WordPress National Weather Service Alerts plugin <= 1.3.5 - Local File Inclusion VulnerabilityJohn Russell National Weather Service Alerts
CVE-2025-47689WordPress Video Blogster Lite plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerabilityjohnh10 Video Blogster Lite
CVE-2025-46465WordPress Print Science Designer plugin <= 1.3.155 - CSRF to Stored XSS vulnerabilityJohn Weissberg Print Science Designer
CVE-2025-4587A/B Testing for WordPress <= 1.18.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingjohnjamesjacoby A/B Testing for WordPress
CVE-2025-43876iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection -…Johnson Controls iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR…
CVE-2025-43875iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection -…Johnson Controls iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR…
CVE-2025-43873iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection -…Johnson Control iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra…
CVE-2025-3750Network Posts Extended <= 7.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_height Parameterjohnzenausa Network Posts Extended
CVE-2025-32671WordPress Print Science Designer plugin <= 1.3.155 - Arbitrary File Download vulnerabilityJohn Weissberg Print Science Designer
CVE-2025-32166WordPress Emma for WordPress plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerabilityJohn Housholder Emma for WordPress
CVE-2025-31524WordPress WP User Profiles plugin <= 2.6.2 - Privilege Escalation vulnerabilityJohn James Jacoby WP User Profiles
CVE-2025-26909WordPress Hide My WP Ghost plugin <= 5.4.01 - Local File Inclusion to RCE vulnerabilityJohn Darrel Hide My WP Ghost
CVE-2025-26386Stack-based Buffer Overflow in Johnson Controls iSTAR Configuration Utility (ICU) toolJohnson Controls iSTAR Configuration Utility (ICU)
CVE-2025-26385Metasys product command injection vulnerability could allow remote SQL executionJohnson Controls Metasys
CVE-2025-26383no title heldJohnson Controls iSTAR Configuration Utility (ICU)
CVE-2025-26382Johnson Controls Software House iSTAR Configuration Utility (ICU) ToolJohnson Controls iSTAR Configuration Utility (ICU)
CVE-2025-26381OpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly FM Systems)Johnson Controls OpenBlue Workplace (formerly FM Systems)
CVE-2025-26379Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number GeneratorJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
CVE-2025-2056WP Ghost <= 5.4.01 - Unauthenticated Limited File Readjohndarrel WP Ghost (Hide My WP Ghost) – Security & Firewall
CVE-2025-1435bbPress <= 2.6.11 - Cross-Site Request Forgery to Limited Privilege Escalationjohnjamesjacoby bbPress
CVE-2025-12524Post Type Switcher <= 4.0.0 - Insecure Direct Object Reference to Authenticated (Author+) Post Type Changejohnjamesjacoby Post Type Switcher
CVE-2025-10182dbview <= 0.5.5 - Authenticated (Contributor+) Stored Cross-Site Scriptingjohn-ackers dbview
CVE-2024-56015WordPress Tidy Up Plugin <= 1.3 - CSRF to Reflected Cross-Site Scripting vulnerabilityJohn Godley Tidy Up
CVE-2024-5224Easy Social Like Box – Popup – Sidebar Widget <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…johnnash1975 Easy Social Like Box – Popup – Sidebar Widget
CVE-2024-51704WordPress imPress plugin <= 0.1.4 - Reflected Cross Site Scripting (XSS) vulnerabilityJohn Hanusek imPress
CVE-2024-35778WordPress Slideshow SE plugin <= 2.5.17 - Auth. Limited Local File Inclusion vulnerabilityJohn West Slideshow SE
CVE-2024-35769WordPress Slideshow SE plugin <= 2.5.17 - Cross Site Scripting (XSS) vulnerabilityJohn West Slideshow SE
CVE-2024-32932American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - stored web interfaceJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32931exacqVison - Token Disclosed in URLJohnson Controls exacqVision
CVE-2024-32865exacqVison - TLS certificate validationJohnson Controls exacqVision
CVE-2024-32864exacqVison - HTTPS Session EstablishmentJohnson Controls exacqVision
CVE-2024-32863exacqVison - CSRF issues with Web ServiceJohnson Controls exacqVision
CVE-2024-32862exacqVision CORSJohnson Controls exacqVision
CVE-2024-32861Software House C•CURE - CouchDB executable protectionJohnson Controls Software House C•CURE 9000 Installer
CVE-2024-32759Johnson Controls Software House C●CURE 9000 installer password strengthJohnson Controls Software House C•CURE 9000
CVE-2024-32758exacqVision - Key exchangesJohnson Controls exacqVision
CVE-2024-32757American Dynamics Illustra Essentials Gen 4 - Linux Credential LeakJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32756American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - LinuxJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32755American Dynamics Illustra Essentials Gen 4 - Log Filter Input ValidationJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32754Johnson Controls Kantech KT1, KT2, and KT400 Door Controllers - Exposure of Sensitive InformationJohnson Controls Kantech KT400 Door Controller, Rev01
CVE-2024-32753TYCO Illustra Pro Gen 4 - JQuery versionJohnson Controls TYCO Illustra Flex4 DualSensor Cameras
CVE-2024-32752Johnson Controls Software House iSTAR Configuration Utility (ICU) ToolJohnson Controls iSTAR Ultra and Ultra LT
CVE-2024-28850WP Crontrol possible RCE when combined with a pre-conditionjohnbillion wp-crontrol
CVE-2024-24802WordPress JTRT Responsive Tables Plugin <= 4.1.9 is vulnerable to Cross Site Request Forgery (CSRF)John Tendik JTRT Responsive Tables
CVE-2024-13794Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosurejohndarrel WP Ghost (Hide My WP Ghost) – Security & Firewall
CVE-2024-13589YouTube Playlists with Schema <= 2.6.1 - Authenticated (Contributor+) Stored Cross-Site Scriptingjohnnya23 YouTube Playlists with Schema
CVE-2024-12312Print Science Designer <= 1.3.152 - Unauthenticated PHP Object Injectionjohnwwweissberg Print Science Designer
CVE-2024-10825Hide My WP Ghost – Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URLjohndarrel WP Ghost (Hide My WP Ghost) – Security & Firewall
CVE-2024-0912CCURE passwords exposed to administratorsJohnson Controls Software House C•CURE 9000
CVE-2023-5085Advanced Menu Widget <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodejohnnypea Advanced Menu Widget
CVE-2023-4804Quantum HD UnityJohnson Controls Quantum HD Unity Interface
CVE-2023-4486Uncontrolled Resource Consumption in Metasys and Facility ExplorerJohnson Controls Facility Explorer F4-SNC
CVE-2023-4276Absolute Privacy <= 2.1 - Cross-Site Request Forgery to User Email/Password Changejohnkolbert Absolute Privacy
CVE-2023-3548IQ Wifi 6Johnson Controls IQ Wifi 6
CVE-2023-35098WordPress NextGen GalleryView Plugin <= 0.5.5 is vulnerable to Cross Site Scripting (XSS)John Brien WordPress NextGen GalleryView
CVE-2023-34185WordPress NextGen GalleryView Plugin <= 0.5.5 is vulnerable to Cross Site Request Forgery (CSRF)John Brien WordPress NextGen GalleryView
CVE-2023-32584WordPress eBecas Plugin <= 3.1.3 is vulnerable to Cross Site Scripting (XSS)John Newcombe eBecas
CVE-2023-2025Exposure of Sensitive Information in OpenBlue Enterprise Manager Data CollectorJohnson Controls OpenBlue Enterprise Manager Data Collector
CVE-2023-2024Improper Authentication for OpenBlue Enterprise Manager Data CollectorJohnson Controls OpenBlue Enterprise Manager Data Collector
CVE-2022-4537Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypassjohndarrel WP Ghost (Hide My WP Ghost) – Security & Firewall
CVE-2022-43461WordPress Slideshow SE Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)John West Slideshow SE
CVE-2022-41554WordPress Slideshow SE Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)John West Slideshow SE
CVE-2022-21941iSTAR UltraJohnson Controls iSTAR Ultra
CVE-2022-21940Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT)Johnson Controls System Configuration Tool (SCT)
CVE-2022-21939Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)Johnson Controls System Configuration Tool (SCT)
CVE-2022-21938Metasys MUI Graphics XSSJohnson Controls Metasys ADS/ADX/OAS server
CVE-2022-21937Metasys CSSJohnson Controls Metasys ADS/ADX/OAS server
CVE-2022-21935Metasys password guessingJohnson Controls Metasys ADS/ADX/OAS server
CVE-2022-21934Metasys Unverified Password ChangeJohnson Controls Metasys ADS/ADX/OAS server
CVE-2021-36207Metasys privilege managementJohnson Controls Metasys ADS/ADX/OAS server
CVE-2021-36206CEVASJohnson Controls CEVAS
CVE-2021-36205Metasys session tokenJohnson Controls Metasys
CVE-2021-36204Insufficiently Protected Credentials in MetasysJohnson Controls Metasys ADS/ADX/OAS
CVE-2021-36203Johnson Controls Metasys SCT ProJohnnson Controls Metasys System Configuration Tool Pro…
CVE-2021-36202Metasys UIJohnson Controls Metasys
CVE-2021-36201CCURE Observable Response DiscrepancyJohnson Controls C•CURE 9000
CVE-2021-36200Metasys ADS/ADX/OAS with MUIJohnson Controls Metasys ADS/ADX/OAS server
CVE-2021-36199VideoEdgeJohnson Controls VideoEdge
CVE-2021-36198EntrapassJohnson Controls Entrapass
CVE-2021-27665exacqVision Server 32-bitJohnson Controls exacqVision Web Service
CVE-2021-27664exacqVision Web ServiceJohnson Controls exacqVision Web Service
CVE-2021-27663CEM Systems AC2000Johnson Controls CEM Systems AC2000
CVE-2021-27662KT-1 Capture-replayJohnson Controls KT-1
CVE-2021-27661Facility ExplorerJohnson Controls Facility Explorer SNC Series Supervisory…
CVE-2021-27660C-CURE 9000Johnson Controls C-CURE 9000
CVE-2021-27659exacqVision Web Service CSSJohnson Controls exacqVision Web Service
CVE-2021-27658exacqVision Enterprise Manager CSSJohnson Controls exacqVision Enterprise Manager
CVE-2021-27657Metasys Improper Privilege ManagementJohnson Controls Metasys
CVE-2021-27656exacqVision Web Services - Information ExposureJohnson Controls exacqVision Web Service version 20.12.2.0…
CVE-2020-9050Metasys Reporting Engine (MRE) Web Services - Improper Limitation of a Pathname to a Restricted Directory ('Path…Johnson Controls Metasys Reporting Engine (MRE) Web…
CVE-2020-9049victor Web Client and C•CURE Web Client JSON Web Token (JWT) VulnerabilityJohnson Controls C•CURE Web Client version 2.90 and prior…
CVE-2020-9048victor Web Client - Arbitrary File Deletion VulnerabilityJohnson Controls victor Web Client version 5.4.1 and prior
CVE-2020-9047exacqVision Software - Improper Verification of Cryptographic SignatureJohnson Controls exacqVision Enterprise Manager versions…
CVE-2020-9046Kantech EntraPass Security Management Software - System Permissions VulnerabilityJohnson Controls Kantech EntraPass Security Management…
CVE-2020-9045C•CURE 9000 and victor Video Management System - Cleartext storage of user credentials upon installation or upgrade of…Johnson Controls American Dynamics victor Video Management…
CVE-2020-9044Metasys Improper Restriction of XML External Entity ReferenceJohnson Controls Metasys Smoke Control Network Automation…
CVE-2020-15167Arbitrary code execution via configuration file in Millerjohnkerl miller
CVE-2019-7594Metasys use of hardcoded RC2 keyJohnson Controls Metasys versions prior to 9.0
CVE-2019-7593Metasys use of shared RSA key pairsJohnson Controls Metasys versions prior to 9.0
CVE-2019-7589Kantech EntraPass Improper Input ValidationJohnson Controls Kantech EntraPass Global Edition
CVE-2018-10624Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive InformationJohnson Controls BCPro (BCM)
CVE-2014-125065john5223 bottle-auth sql injectionjohn5223 bottle-auth

151 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.