Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.66.76.86.97.07.12024202520262027

Недавние уязвимости WordPress

Количество 1 914

nvd логотип

CVE-2012-2371

около 14 лет назад

Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb parameter.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2012-3385

около 14 лет назад

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3385

около 14 лет назад

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3384

около 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in W ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-3384

около 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-3383

около 14 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-3383

около 14 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-3383

около 14 лет назад

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-3384

около 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-3385

около 14 лет назад

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-2371

Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb parameter.

CVSS2: 4.3
13%
Средний
около 14 лет назад
debian логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in W ...

CVSS2: 6.8
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress ...

CVSS2: 2.6
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3383

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

CVSS2: 2.6
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
2%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться