Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 896

nvd логотип

CVE-2013-4340

около 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4340

около 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-4339

около 12 лет назад

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-4339

около 12 лет назад

WordPress before 3.6.1 does not properly validate URLs before use in a ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4340

около 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-5739

около 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-5738

около 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-4339

около 12 лет назад

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-4338

около 12 лет назад

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-4338

около 12 лет назад

wp-includes/functions.php in WordPress before 3.6.1 does not properly ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
1%
Низкий
около 12 лет назад
debian логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-4339

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
1%
Низкий
около 12 лет назад
debian логотип
CVE-2013-4339

WordPress before 3.6.1 does not properly validate URLs before use in a ...

CVSS2: 7.5
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-4339

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-4338

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

CVSS2: 7.5
10%
Низкий
около 12 лет назад
debian логотип
CVE-2013-4338

wp-includes/functions.php in WordPress before 3.6.1 does not properly ...

CVSS2: 7.5
10%
Низкий
около 12 лет назад

Уязвимостей на страницу


Поделиться