WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 894
CVE-2014-9036
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3. ...

CVE-2014-9035
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-9035
Cross-site scripting (XSS) vulnerability in Press This in WordPress be ...

CVE-2014-9034
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.
CVE-2014-9034
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3 ...

CVE-2014-9033
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.
CVE-2014-9033
Cross-site request forgery (CSRF) vulnerability in wp-login.php in Wor ...

CVE-2014-9032
Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-9032
Cross-site scripting (XSS) vulnerability in the media-playlists featur ...

CVE-2014-9031
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2014-9036 Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3. ... | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад | |
![]() | CVE-2014-9035 Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад |
CVE-2014-9035 Cross-site scripting (XSS) vulnerability in Press This in WordPress be ... | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад | |
![]() | CVE-2014-9034 wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016. | CVSS2: 5 | 72% Высокий | почти 11 лет назад |
CVE-2014-9034 wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3 ... | CVSS2: 5 | 72% Высокий | почти 11 лет назад | |
![]() | CVE-2014-9033 Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords. | CVSS2: 6.8 | 1% Низкий | почти 11 лет назад |
CVE-2014-9033 Cross-site request forgery (CSRF) vulnerability in wp-login.php in Wor ... | CVSS2: 6.8 | 1% Низкий | почти 11 лет назад | |
![]() | CVE-2014-9032 Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад |
CVE-2014-9032 Cross-site scripting (XSS) vulnerability in the media-playlists featur ... | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад | |
![]() | CVE-2014-9031 Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post. | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад |
Уязвимостей на страницу