WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 894

CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

CVE-2019-17671
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVE-2019-17669
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

CVE-2019-17675
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated us ...

CVE-2019-16222
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
CVE-2019-16222
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_b ...

CVE-2019-16221
WordPress before 5.2.3 allows reflected XSS in the dashboard.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2019-17670 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. | CVSS3: 9.8 | 5% Низкий | почти 6 лет назад |
![]() | CVE-2019-17672 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. | CVSS3: 6.1 | 3% Низкий | почти 6 лет назад |
![]() | CVE-2019-17671 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | CVSS3: 5.3 | 73% Высокий | почти 6 лет назад |
![]() | CVE-2019-17669 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. | CVSS3: 9.8 | 11% Средний | почти 6 лет назад |
![]() | CVE-2019-17675 WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. | CVSS3: 8.8 | 4% Низкий | почти 6 лет назад |
![]() | CVE-2019-16223 WordPress before 5.2.3 allows XSS in post previews by authenticated users. | CVSS3: 5.4 | 4% Низкий | почти 6 лет назад |
CVE-2019-16223 WordPress before 5.2.3 allows XSS in post previews by authenticated us ... | CVSS3: 5.4 | 4% Низкий | почти 6 лет назад | |
![]() | CVE-2019-16222 WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад |
CVE-2019-16222 WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_b ... | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад | |
![]() | CVE-2019-16221 WordPress before 5.2.3 allows reflected XSS in the dashboard. | CVSS3: 6.1 | 1% Низкий | почти 6 лет назад |
Уязвимостей на страницу