Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

nvd логотип

CVE-2013-5918

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5917

почти 13 лет назад

SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-5739

почти 13 лет назад

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-5739

почти 13 лет назад

The default configuration of WordPress before 3.6.1 does not prevent u ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-5738

почти 13 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-5738

почти 13 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in Wo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4340

почти 13 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4340

почти 13 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-4339

почти 13 лет назад

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-4339

почти 13 лет назад

WordPress before 3.6.1 does not properly validate URLs before use in a ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-5918

Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5917

SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter.

CVSS2: 7.5
3%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
2%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent u ...

CVSS2: 3.5
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in Wo ...

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
3%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
3%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-4339

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
7%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-4339

WordPress before 3.6.1 does not properly validate URLs before use in a ...

CVSS2: 7.5
7%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться