WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 896
CVE-2013-2199
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.
CVE-2013-2199
The HTTP API in WordPress before 3.5.2 allows remote attackers to send ...
CVE-2013-0237
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2013-0237
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode p ...
CVE-2013-0236
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
CVE-2013-0236
Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...
CVE-2013-0235
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.
CVE-2013-0235
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to se ...
CVE-2013-2201
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.
CVE-2013-0235
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2013-2199 The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235. | CVSS2: 4.3 | 1% Низкий | больше 12 лет назад | |
CVE-2013-2199 The HTTP API in WordPress before 3.5.2 allows remote attackers to send ... | CVSS2: 4.3 | 1% Низкий | больше 12 лет назад | |
CVE-2013-0237 Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. | CVSS2: 4.3 | 0% Низкий | больше 12 лет назад | |
CVE-2013-0237 Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode p ... | CVSS2: 4.3 | 0% Низкий | больше 12 лет назад | |
CVE-2013-0236 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post. | CVSS2: 4.3 | 0% Низкий | больше 12 лет назад | |
CVE-2013-0236 Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ... | CVSS2: 4.3 | 0% Низкий | больше 12 лет назад | |
CVE-2013-0235 The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue. | CVSS2: 6.4 | 65% Средний | больше 12 лет назад | |
CVE-2013-0235 The XMLRPC API in WordPress before 3.5.1 allows remote attackers to se ... | CVSS2: 6.4 | 65% Средний | больше 12 лет назад | |
CVE-2013-2201 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes. | CVSS2: 4.3 | 1% Низкий | больше 12 лет назад | |
CVE-2013-0235 The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue. | CVSS2: 6.4 | 65% Средний | больше 12 лет назад |
Уязвимостей на страницу