WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 894

CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject ...

CVE-2019-17671
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVE-2019-17671
In WordPress before 5.2.4, unauthenticated viewing of certain content ...

CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ...

CVE-2019-17669
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVE-2019-17669
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ...

CVE-2019-17669
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

CVE-2019-17673
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2019-17672 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. | CVSS3: 6.1 | 3% Низкий | почти 6 лет назад |
CVE-2019-17672 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject ... | CVSS3: 6.1 | 3% Низкий | почти 6 лет назад | |
![]() | CVE-2019-17671 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | CVSS3: 5.3 | 73% Высокий | почти 6 лет назад |
CVE-2019-17671 In WordPress before 5.2.4, unauthenticated viewing of certain content ... | CVSS3: 5.3 | 73% Высокий | почти 6 лет назад | |
![]() | CVE-2019-17670 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. | CVSS3: 9.8 | 5% Низкий | почти 6 лет назад |
CVE-2019-17670 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ... | CVSS3: 9.8 | 5% Низкий | почти 6 лет назад | |
![]() | CVE-2019-17669 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. | CVSS3: 9.8 | 11% Средний | почти 6 лет назад |
CVE-2019-17669 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ... | CVSS3: 9.8 | 11% Средний | почти 6 лет назад | |
![]() | CVE-2019-17669 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. | CVSS3: 9.8 | 11% Средний | почти 6 лет назад |
![]() | CVE-2019-17673 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. | CVSS3: 7.5 | 4% Низкий | почти 6 лет назад |
Уязвимостей на страницу