Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

ubuntu логотип

CVE-2017-17093

больше 8 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17091

больше 8 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-16510

почти 9 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-16510

почти 9 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-16510

почти 9 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2012-6707

почти 9 лет назад

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2012-6707

почти 9 лет назад

WordPress through 4.8.2 uses a weak MD5-based password hashing algorit ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6707

почти 9 лет назад

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-9263

почти 9 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2016-9263

почти 9 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandb ...

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
7%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
7%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
7%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
7%
Низкий
почти 9 лет назад
nvd логотип
CVE-2012-6707

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2012-6707

WordPress through 4.8.2 uses a weak MD5-based password hashing algorit ...

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2012-6707

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-9263

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
2%
Низкий
почти 9 лет назад
debian логотип
CVE-2016-9263

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandb ...

CVSS3: 4.7
2%
Низкий
почти 9 лет назад

Уязвимостей на страницу


Поделиться