Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

nvd логотип

CVE-2005-2107

почти 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2005-2110

почти 20 лет назад

WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensit ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2109

почти 20 лет назад

wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2107

почти 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in post.php in Wor ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2005-2108

почти 20 лет назад

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2107

почти 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2108

почти 20 лет назад

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2109

почти 20 лет назад

wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2110

почти 20 лет назад

WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1810

около 20 лет назад

SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2005-2107

Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2110

WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensit ...

CVSS2: 5
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2109

wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers ...

CVSS2: 5
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2107

Multiple cross-site scripting (XSS) vulnerabilities in post.php in Wor ...

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2005-2108

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and ...

CVSS2: 7.5
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2005-2107

Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2005-2108

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

CVSS2: 7.5
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2005-2109

wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.

CVSS2: 5
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2005-2110

WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.

CVSS2: 5
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2005-1810

SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.

CVSS2: 7.5
2%
Низкий
около 20 лет назад

Уязвимостей на страницу


Поделиться