WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 896
CVE-2013-1409
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.
CVE-2014-1888
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.
CVE-2012-6635
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.
CVE-2012-6635
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3. ...
CVE-2012-6634
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
CVE-2012-6634
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...
CVE-2012-6633
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
CVE-2012-6633
Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...
CVE-2011-5270
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
CVE-2011-5270
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2013-1409 Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php. | CVSS2: 4.3 | 3% Низкий | больше 11 лет назад | |
CVE-2014-1888 Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889. | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад | |
CVE-2012-6635 wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft. | CVSS2: 4 | 1% Низкий | почти 12 лет назад | |
CVE-2012-6635 wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3. ... | CVSS2: 4 | 1% Низкий | почти 12 лет назад | |
CVE-2012-6634 wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value. | CVSS2: 6.4 | 1% Низкий | почти 12 лет назад | |
CVE-2012-6634 wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ... | CVSS2: 6.4 | 1% Низкий | почти 12 лет назад | |
CVE-2012-6633 Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field. | CVSS2: 4.3 | 0% Низкий | почти 12 лет назад | |
CVE-2012-6633 Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ... | CVSS2: 4.3 | 0% Низкий | почти 12 лет назад | |
CVE-2011-5270 wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role. | CVSS2: 4 | 1% Низкий | почти 12 лет назад | |
CVE-2011-5270 wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the ... | CVSS2: 4 | 1% Низкий | почти 12 лет назад |
Уязвимостей на страницу