Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

nvd логотип

CVE-2016-9263

почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2016-9263

почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandb ...

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2016-9263

почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2017-14990

почти 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2017-14990

почти 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14990

почти 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-14726

почти 8 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-14726

почти 8 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripti ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-14725

почти 8 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-14725

почти 8 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect at ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-9263

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2016-9263

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandb ...

CVSS3: 4.7
1%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2016-9263

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but ...

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
3%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripti ...

CVSS3: 6.1
3%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
3%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect at ...

CVSS3: 5.4
3%
Низкий
почти 8 лет назад

Уязвимостей на страницу


Поделиться