Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 896

nvd логотип

CVE-2018-20153

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-20153

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-20152

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2018-20152

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass i ...

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2018-20151

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-20151

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation pa ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-20150

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-20150

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could tri ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-20149

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-20149

почти 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP S ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
5%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ...

CVSS3: 5.4
5%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
12%
Средний
почти 7 лет назад
debian логотип
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass i ...

CVSS3: 6.5
12%
Средний
почти 7 лет назад
nvd логотип
CVE-2018-20151

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
7%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-20151

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation pa ...

CVSS3: 7.5
7%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-20150

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
7%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-20150

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could tri ...

CVSS3: 6.1
7%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-20149

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
4%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-20149

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP S ...

CVSS3: 5.4
4%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться