Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"
WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.36.46.56.66.76.82023202420252026

Недавние уязвимости WordPress

Количество 1 896

nvd логотип

CVE-2017-5491

почти 9 лет назад

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-5491

почти 9 лет назад

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-5490

почти 9 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5490

почти 9 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5489

почти 9 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-5489

почти 9 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-5488

почти 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5488

почти 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5487

почти 9 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
EPSS: Критический
debian логотип

CVE-2017-5487

почти 9 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2017-5491

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

CVSS3: 5.3
2%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-5491

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to ...

CVSS3: 5.3
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...

CVSS3: 6.1
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...

CVSS3: 8.8
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...

CVSS3: 6.1
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
92%
Критический
почти 9 лет назад
debian логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
92%
Критический
почти 9 лет назад

Уязвимостей на страницу


Поделиться