Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.66.76.86.97.07.12024202520262027

Недавние уязвимости WordPress

Количество 1 914

nvd логотип

CVE-2009-4748

больше 16 лет назад

SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-4672

больше 16 лет назад

Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pg parameter.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2010-0682

больше 16 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read t ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2010-0682

больше 16 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2010-0682

больше 16 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2010-0673

больше 16 лет назад

SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-4424

больше 16 лет назад

SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3703

больше 16 лет назад

Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the search_max parameter in a search action to the default URI, related to wpf.class.php; (2) the forum parameter to an unspecified component, related to wpf.class.php; (3) the topic parameter in a viewforum action to the default URI, related to the remove_topic function in wpf.class.php; or the id parameter in a (4) editpost or (5) viewtopic action to the default URI, related to wpf-post.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-4170

почти 17 лет назад

WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-4169

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2009-4748

SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-4672

Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pg parameter.

CVSS2: 7.5
9%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read t ...

CVSS2: 4
10%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
10%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
10%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0673

SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-4424

SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3703

Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the search_max parameter in a search action to the default URI, related to wpf.class.php; (2) the forum parameter to an unspecified component, related to wpf.class.php; (3) the topic parameter in a viewforum action to the default URI, related to the remove_topic function in wpf.class.php; or the id parameter in a (4) editpost or (5) viewtopic action to the default URI, related to wpf-post.php.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-4170

WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.

CVSS2: 5
6%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-4169

Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
2%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться