Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.66.76.86.97.07.12024202520262027

Недавние уязвимости WordPress

Количество 1 914

github логотип

GHSA-pj25-83q9-ppf3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6r5w-j94p-fpmf

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-893q-vmc7-qcvh

больше 4 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fgx-wpwv-vr2r

больше 4 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8688-jv8f-2mcf

больше 4 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q59q-2whf-h2x9

больше 4 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cv88-x229-26m4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-277w-qpxr-2549

больше 4 лет назад

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xg6f-394q-j4f9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

EPSS: Средний
github логотип

GHSA-wfch-pm8w-hchp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-pj25-83q9-ppf3

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-6r5w-j94p-fpmf

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-893q-vmc7-qcvh

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4fgx-wpwv-vr2r

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-8688-jv8f-2mcf

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-q59q-2whf-h2x9

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-cv88-x229-26m4

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
6%
Низкий
больше 4 лет назад
github логотип
GHSA-277w-qpxr-2549

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
7%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6f-394q-j4f9

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

17%
Средний
больше 4 лет назад
github логотип
GHSA-wfch-pm8w-hchp

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

5%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться