WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 894

CVE-2010-5296
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
CVE-2010-5296
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

CVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
CVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...

CVE-2010-5294
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
CVE-2010-5294
Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...

CVE-2010-5293
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
CVE-2010-5293
wp-includes/comment.php in WordPress before 3.0.2 does not properly wh ...

CVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVE-2010-5296
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2010-5296 wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. | CVSS2: 4.9 | 0% Низкий | больше 11 лет назад |
CVE-2010-5296 wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ... | CVSS2: 4.9 | 0% Низкий | больше 11 лет назад | |
![]() | CVE-2010-5295 Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action. | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад |
CVE-2010-5295 Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ... | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад | |
![]() | CVE-2010-5294 Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt. | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад |
CVE-2010-5294 Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ... | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
![]() | CVE-2010-5293 wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match. | CVSS2: 5.8 | 0% Низкий | больше 11 лет назад |
CVE-2010-5293 wp-includes/comment.php in WordPress before 3.0.2 does not properly wh ... | CVSS2: 5.8 | 0% Низкий | больше 11 лет назад | |
![]() | CVE-2010-5295 Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action. | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад |
![]() | CVE-2010-5296 wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. | CVSS2: 4.9 | 0% Низкий | больше 11 лет назад |
Уязвимостей на страницу