diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml
index ad75c218..d06857ee 100644
--- a/data/plugin_vulns.xml
+++ b/data/plugin_vulns.xml
@@ -593,11 +593,12 @@
- SWF Vulnerable to XSS Bundled in Many WordPress Plugins
+ Comment Extra Field 1.7 - CSRF / XSS
+ http://packetstormsecurity.com/files/122625/
http://brindi.si/g/blog/vulnerable-swf-bundled-in-wordpress-plugins.html
- XSS
+ MULTI
@@ -3020,11 +3021,34 @@
MULTI
- Mingle Forum 1.0.33.3 - Multiple Parameter SQL Injection
+ Mingle Forum 1.0.33.3 - fs-admin.php togroupusers Parameter XSS
+
+ 90432
+ 2013-0734
+ 52167
+
+ XSS
+ 1.0.34
+
+
+ Mingle Forum 1.0.33.3 - wpf.class.php search_words Parameter XSS
+
+ 90433
+ 2013-0734
+ 52167
+
+ XSS
+ 1.0.34
+
+
+ Mingle Forum 1.0.33.3 - wpf.class.php Multiple Parameter SQL Injection
90434
+ 2013-0735
+ 52167
SQLI
+ 1.0.34
Mingle Forum 1.0.35 - Privilege Escalation CSRF
@@ -5860,8 +5884,10 @@
- Terillion Reviews - Cross Site Scripting
+ Terillion Reviews - Profile Id Field XSS
+ 91123
+ 2013-1201
http://packetstormsecurity.com/files/120730/
XSS
@@ -6679,6 +6705,7 @@
Xorbin Digital Flash Clock 1.0 - Flash-based XSS
+ http://packetstormsecurity.com/files/122223/
http://advisory.prakharprasad.com/xorbin_dfc_wp.txt
2013-4693
@@ -6756,6 +6783,7 @@
95557
26804
+ http://packetstormsecurity.com/files/122396/
RFI
@@ -7080,7 +7108,7 @@
- LBG Zoominoutslider - XSS Vulnerability
+ LBG Zoominoutslider - add_banner.php name Parameter Stored XSS
97887
54983
@@ -7088,6 +7116,30 @@
XSS
+
+ LBG Zoominoutslider - settings_form.php Multiple Parameter Stored XSS
+
+ 99339
+ http://seclists.org/fulldisclosure/2013/Nov/30
+
+ XSS
+
+
+ LBG Zoominoutslider - add_playlist_record.php Multiple Parameter Stored XSS
+
+ 99340
+ http://seclists.org/fulldisclosure/2013/Nov/30
+
+ XSS
+
+
+ LBG Zoominoutslider - Multiple Script Direct Request Path Disclosure
+
+ 99341
+ http://seclists.org/fulldisclosure/2013/Nov/30
+
+ FPD
+
@@ -7206,8 +7258,10 @@
Booking Calendar 4.1.4 - CSRF Vulnerability
- 27399
96088
+ 27399
+ 54461
+ http://packetstormsecurity.com/files/122691/
http://wpbookingcalendar.com/
CSRF
@@ -7233,10 +7287,12 @@
98279
28808
+ 55172
http://packetstormsecurity.com/files/123549/
http://quick-plugins.com/quick-contact-form/
XSS
+ 6.1
@@ -7569,6 +7625,7 @@
Feed - news_dt.php nid Parameter SQL Injection
94804
+ http://packetstormsecurity.com/files/122260/
SQLI
@@ -7725,6 +7782,7 @@
98831
2013-6281
55396
+ http://packetstormsecurity.com/files/123699/
http://www.securityfocus.com/bid/63256
XSS
@@ -7820,5 +7878,18 @@
+
+
+ Facebook Survey Pro - timeline/index.php id Parameter SQL Injection
+
+ 87817
+ 22853
+ http://packetstormsecurity.com/files/118238/
+ http://www.securityfocus.com/bid/56595
+ http://xforce.iss.net/xforce/xfdb/80141
+
+ SQLI
+
+
diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml
index 4cf4030a..3b6e583d 100644
--- a/data/theme_vulns.xml
+++ b/data/theme_vulns.xml
@@ -1897,4 +1897,24 @@
+
+
+ ThisWay - remote shell upload vulnerability
+
+ http://packetstormsecurity.com/files/123895/
+
+ RCE
+
+
+
+
+
+ Think Responsive 1.0 - Arbitrary shell upload vulnerability
+
+ http://packetstormsecurity.com/files/123880/
+
+ RCE
+
+
+