Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 894

nvd логотип

CVE-2017-5490

больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5490

больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5489

больше 8 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-5489

больше 8 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-5488

больше 8 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5488

больше 8 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5487

больше 8 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
EPSS: Критический
debian логотип

CVE-2017-5487

больше 8 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
EPSS: Критический
ubuntu логотип

CVE-2017-5490

больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-5489

больше 8 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...

CVSS3: 8.8
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
92%
Критический
больше 8 лет назад
debian логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
92%
Критический
больше 8 лет назад
ubuntu логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
1%
Низкий
больше 8 лет назад

Уязвимостей на страницу


Поделиться