Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.46.56.66.76.86.920232024202520262027

Недавние уязвимости WordPress

Количество 1 906

ubuntu логотип

CVE-2015-3440

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2015-5623

больше 10 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
EPSS: Средний
nvd логотип

CVE-2015-3429

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3429

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-3429

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9039

около 11 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9039

около 11 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x befo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9038

около 11 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2014-9038

около 11 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3. ...

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2014-9037

около 11 лет назад

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2015-3440

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

CVSS2: 4.3
10%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
48%
Средний
больше 10 лет назад
nvd логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons ...

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9039

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
2%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9039

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x befo ...

CVSS2: 4.3
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
1%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3. ...

CVSS2: 6.4
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9037

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
3%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться