Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

nvd логотип

CVE-2014-3843

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-3841

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Label field, related to form layout configuration. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-3210

больше 11 лет назад

SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2013-2706

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-0166

больше 11 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2014-0166

больше 11 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in W ...

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2014-0165

больше 11 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0165

больше 11 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authentica ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-0166

больше 11 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2014-0165

больше 11 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-3843

Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-3841

Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Label field, related to form layout configuration. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-3210

SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.

CVSS2: 6.5
3%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-2706

Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
35%
Средний
больше 11 лет назад
debian логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in W ...

CVSS2: 6.4
35%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authentica ...

CVSS2: 4
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
35%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться