Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

debian логотип

CVE-2016-10045

больше 9 лет назад

The isMail transport in PHPMailer before 5.2.20 might allow remote att ...

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2016-10033

больше 9 лет назад

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2016-10033

больше 9 лет назад

The mailSend function in the isMail transport in PHPMailer before 5.2. ...

CVSS3: 9.8
EPSS: Критический
ubuntu логотип

CVE-2016-10045

больше 9 лет назад

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

CVSS3: 9.8
EPSS: Критический
ubuntu логотип

CVE-2016-10033

больше 9 лет назад

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2016-6635

почти 10 лет назад

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-6635

почти 10 лет назад

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_comp ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-6634

почти 10 лет назад

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-6634

почти 10 лет назад

Cross-site scripting (XSS) vulnerability in the network settings page ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-4029

почти 10 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-10045

The isMail transport in PHPMailer before 5.2.20 might allow remote att ...

CVSS3: 9.8
98%
Критический
больше 9 лет назад
nvd логотип
CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
100%
Критический
больше 9 лет назад
debian логотип
CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2. ...

CVSS3: 9.8
100%
Критический
больше 9 лет назад
ubuntu логотип
CVE-2016-10045

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

CVSS3: 9.8
98%
Критический
больше 9 лет назад
ubuntu логотип
CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
100%
Критический
больше 9 лет назад
nvd логотип
CVE-2016-6635

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

CVSS3: 8.8
2%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-6635

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_comp ...

CVSS3: 8.8
2%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-6634

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
3%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-6634

Cross-site scripting (XSS) vulnerability in the network settings page ...

CVSS3: 6.1
3%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
4%
Низкий
почти 10 лет назад

Уязвимостей на страницу


Поделиться