Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

debian логотип

CVE-2016-4029

почти 10 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP addres ...

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2016-6634

почти 10 лет назад

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-6635

почти 10 лет назад

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-4029

почти 10 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2016-5839

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5839

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to bypass the sanitize_ ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5838

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5838

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended pass ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5837

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5837

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended acce ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP addres ...

CVSS3: 8.6
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-6634

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
3%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-6635

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

CVSS3: 8.8
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
4%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-5839

WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.

CVSS3: 7.5
3%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5839

WordPress before 4.5.3 allows remote attackers to bypass the sanitize_ ...

CVSS3: 7.5
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5838

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
3%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5838

WordPress before 4.5.3 allows remote attackers to bypass intended pass ...

CVSS3: 7.5
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5837

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
3%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5837

WordPress before 4.5.3 allows remote attackers to bypass intended acce ...

CVSS3: 7.5
3%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться