Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 896

nvd логотип

CVE-2013-2199

больше 12 лет назад

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2199

больше 12 лет назад

The HTTP API in WordPress before 3.5.2 allows remote attackers to send ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0237

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-0237

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode p ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0236

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-0236

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0235

больше 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2013-0235

больше 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to se ...

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2013-2201

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-0235

больше 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-2199

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2199

The HTTP API in WordPress before 3.5.2 allows remote attackers to send ...

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0237

Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-0237

Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode p ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0236

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-0236

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0235

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
65%
Средний
больше 12 лет назад
debian логотип
CVE-2013-0235

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to se ...

CVSS2: 6.4
65%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2013-2201

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-0235

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
65%
Средний
больше 12 лет назад

Уязвимостей на страницу


Поделиться