WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 912
CVE-2022-43504
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43504
Improper authentication vulnerability in WordPress versions prior to 6 ...
CVE-2022-43500
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43500
Cross-site scripting vulnerability in WordPress versions prior to 6.0. ...
CVE-2022-43497
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43497
Cross-site scripting vulnerability in WordPress versions prior to 6.0. ...
CVE-2022-43504
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43497
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43500
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
GHSA-8fxj-85rv-jj93
WordPress before 5.2.3 allows reflected XSS in the dashboard.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-43504 Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43504 Improper authentication vulnerability in WordPress versions prior to 6 ... | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43500 Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43500 Cross-site scripting vulnerability in WordPress versions prior to 6.0. ... | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43497 Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43497 Cross-site scripting vulnerability in WordPress versions prior to 6.0. ... | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43504 Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43497 Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-43500 Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-8fxj-85rv-jj93 WordPress before 5.2.3 allows reflected XSS in the dashboard. | CVSS3: 6.1 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу