WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 894

CVE-2017-5490
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.
CVE-2017-5490
Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...

CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...

CVE-2017-5488
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.
CVE-2017-5488
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...

CVE-2017-5487
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
CVE-2017-5487
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVE-2017-5490
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2017-5490 Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php. | CVSS3: 6.1 | 1% Низкий | больше 8 лет назад |
CVE-2017-5490 Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ... | CVSS3: 6.1 | 1% Низкий | больше 8 лет назад | |
![]() | CVE-2017-5489 Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload. | CVSS3: 8.8 | 1% Низкий | больше 8 лет назад |
CVE-2017-5489 Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ... | CVSS3: 8.8 | 1% Низкий | больше 8 лет назад | |
![]() | CVE-2017-5488 Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin. | CVSS3: 6.1 | 1% Низкий | больше 8 лет назад |
CVE-2017-5488 Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ... | CVSS3: 6.1 | 1% Низкий | больше 8 лет назад | |
![]() | CVE-2017-5487 wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | CVSS3: 5.3 | 92% Критический | больше 8 лет назад |
CVE-2017-5487 wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ... | CVSS3: 5.3 | 92% Критический | больше 8 лет назад | |
![]() | CVE-2017-5490 Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php. | CVSS3: 6.1 | 1% Низкий | больше 8 лет назад |
![]() | CVE-2017-5489 Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload. | CVSS3: 8.8 | 1% Низкий | больше 8 лет назад |
Уязвимостей на страницу