WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 896
CVE-2017-5491
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
CVE-2017-5491
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to ...
CVE-2017-5490
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.
CVE-2017-5490
Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...
CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...
CVE-2017-5488
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.
CVE-2017-5488
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...
CVE-2017-5487
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
CVE-2017-5487
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5491 wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name. | CVSS3: 5.3 | 2% Низкий | почти 9 лет назад | |
CVE-2017-5491 wp-mail.php in WordPress before 4.7.1 might allow remote attackers to ... | CVSS3: 5.3 | 2% Низкий | почти 9 лет назад | |
CVE-2017-5490 Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php. | CVSS3: 6.1 | 1% Низкий | почти 9 лет назад | |
CVE-2017-5490 Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ... | CVSS3: 6.1 | 1% Низкий | почти 9 лет назад | |
CVE-2017-5489 Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload. | CVSS3: 8.8 | 1% Низкий | почти 9 лет назад | |
CVE-2017-5489 Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ... | CVSS3: 8.8 | 1% Низкий | почти 9 лет назад | |
CVE-2017-5488 Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin. | CVSS3: 6.1 | 1% Низкий | почти 9 лет назад | |
CVE-2017-5488 Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ... | CVSS3: 6.1 | 1% Низкий | почти 9 лет назад | |
CVE-2017-5487 wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | CVSS3: 5.3 | 92% Критический | почти 9 лет назад | |
CVE-2017-5487 wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ... | CVSS3: 5.3 | 92% Критический | почти 9 лет назад |
Уязвимостей на страницу