Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 896

nvd логотип

CVE-2013-1409

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1888

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-6635

почти 12 лет назад

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-6635

почти 12 лет назад

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3. ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-6634

почти 12 лет назад

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-6634

почти 12 лет назад

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-6633

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-6633

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5270

почти 12 лет назад

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-5270

почти 12 лет назад

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-1409

Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-1888

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2012-6635

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

CVSS2: 4
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2012-6635

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3. ...

CVSS2: 4
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS2: 6.4
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...

CVSS2: 6.4
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2011-5270

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

CVSS2: 4
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2011-5270

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the ...

CVSS2: 4
1%
Низкий
почти 12 лет назад

Уязвимостей на страницу


Поделиться