Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

ubuntu логотип

CVE-2015-5733

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5734

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5731

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-3439

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3439

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiec ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-3439

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3438

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3438

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-3438

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5623

около 11 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2015-5733

Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.

CVSS2: 4.3
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5734

Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.

CVSS2: 4.3
6%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5731

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVSS2: 6.8
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3439

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
5%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-3439

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiec ...

CVSS2: 4.3
5%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-3439

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
5%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-3438

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
7%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-3438

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
7%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-3438

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
7%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться