Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.46.56.66.76.86.920232024202520262027

Недавние уязвимости WordPress

Количество 1 906

ubuntu логотип

CVE-2016-5838

больше 9 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-5835

больше 9 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-4567

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-4567

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-4566

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-4566

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plup ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-2222

больше 9 лет назад

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2016-2222

больше 9 лет назад

The wp_http_validate_url function in wp-includes/http.php in WordPress ...

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2016-2221

больше 9 лет назад

Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2016-2221

больше 9 лет назад

Open redirect vulnerability in the wp_validate_redirect function in wp ...

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2016-5838

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
2%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
4%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as ...

CVSS3: 6.1
4%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
5%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plup ...

CVSS3: 6.1
5%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2222

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

CVSS3: 8.6
5%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2222

The wp_http_validate_url function in wp-includes/http.php in WordPress ...

CVSS3: 8.6
5%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2221

Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.

CVSS3: 7.4
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2221

Open redirect vulnerability in the wp_validate_redirect function in wp ...

CVSS3: 7.4
3%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться