Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

github логотип

GHSA-pj25-83q9-ppf3

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-893q-vmc7-qcvh

около 4 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fgx-wpwv-vr2r

около 4 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q59q-2whf-h2x9

около 4 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8688-jv8f-2mcf

около 4 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cv88-x229-26m4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-277w-qpxr-2549

около 4 лет назад

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cv8p-7fxf-fmqr

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

EPSS: Низкий
github логотип

GHSA-xg6f-394q-j4f9

около 4 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

EPSS: Средний
github логотип

GHSA-wfch-pm8w-hchp

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-pj25-83q9-ppf3

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-893q-vmc7-qcvh

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-4fgx-wpwv-vr2r

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-q59q-2whf-h2x9

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-8688-jv8f-2mcf

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-cv88-x229-26m4

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
5%
Низкий
около 4 лет назад
github логотип
GHSA-277w-qpxr-2549

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
6%
Низкий
около 4 лет назад
github логотип
GHSA-cv8p-7fxf-fmqr

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

8%
Низкий
около 4 лет назад
github логотип
GHSA-xg6f-394q-j4f9

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

18%
Средний
около 4 лет назад
github логотип
GHSA-wfch-pm8w-hchp

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

6%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться