Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

github логотип

GHSA-jpj9-pwx9-945j

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter.

EPSS: Низкий
github логотип

GHSA-jhw4-989v-7prf

больше 3 лет назад

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly other unspecified components.

EPSS: Низкий
github логотип

GHSA-jgj7-cghf-2wq9

около 3 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-jg4j-hqh7-5qcx

около 3 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

EPSS: Средний
github логотип

GHSA-j9fv-vvq8-cm36

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Temporary Uploads editing functionality (wp-admin/includes/upload.php) in WordPress 2.2.1, allows remote attackers to inject arbitrary web script or HTML via the style parameter to wp-admin/upload.php.

EPSS: Низкий
github логотип

GHSA-j6jx-vjmj-5q6h

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

EPSS: Низкий
github логотип

GHSA-j67v-jcp6-qrm3

больше 3 лет назад

** DISPUTED ** Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators. However, it has been patched by at least one vendor.

EPSS: Низкий
github логотип

GHSA-j4jj-c644-q3fc

около 3 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-j2rp-vprg-5m9q

около 3 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-j28g-8c73-vhw9

около 3 лет назад

WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-j273-w3x2-xgpg

около 3 лет назад

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

EPSS: Средний
github логотип

GHSA-j242-vw64-5qc4

около 3 лет назад

In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hw7c-mc39-5vqf

около 3 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

EPSS: Низкий
github логотип

GHSA-hvvp-q39h-2h56

около 3 лет назад

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

EPSS: Низкий
github логотип

GHSA-hqq8-34fg-q5jj

около 3 лет назад

WordPress before 5.2.3 allows XSS in shortcode previews.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hmqr-j9c3-8h75

около 3 лет назад

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-hm6q-fjph-v26v

больше 2 лет назад

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script .

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hm63-rvp6-rvmj

больше 3 лет назад

wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.

EPSS: Низкий
github логотип

GHSA-hhj8-hj4j-7q6w

около 3 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

EPSS: Низкий
github логотип

GHSA-hgh7-wggh-fw3g

около 3 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jpj9-pwx9-945j

Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-jhw4-989v-7prf

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly other unspecified components.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-jgj7-cghf-2wq9

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.

CVSS3: 9.8
46%
Средний
около 3 лет назад
github логотип
GHSA-jg4j-hqh7-5qcx

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

35%
Средний
около 3 лет назад
github логотип
GHSA-j9fv-vvq8-cm36

Cross-site scripting (XSS) vulnerability in the Temporary Uploads editing functionality (wp-admin/includes/upload.php) in WordPress 2.2.1, allows remote attackers to inject arbitrary web script or HTML via the style parameter to wp-admin/upload.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-j6jx-vjmj-5q6h

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

1%
Низкий
около 3 лет назад
github логотип
GHSA-j67v-jcp6-qrm3

** DISPUTED ** Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators. However, it has been patched by at least one vendor.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-j4jj-c644-q3fc

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
11%
Средний
около 3 лет назад
github логотип
GHSA-j2rp-vprg-5m9q

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-j28g-8c73-vhw9

WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-j273-w3x2-xgpg

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

11%
Средний
около 3 лет назад
github логотип
GHSA-j242-vw64-5qc4

In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.

CVSS3: 6.1
5%
Низкий
около 3 лет назад
github логотип
GHSA-hw7c-mc39-5vqf

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

0%
Низкий
около 3 лет назад
github логотип
GHSA-hvvp-q39h-2h56

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

1%
Низкий
около 3 лет назад
github логотип
GHSA-hqq8-34fg-q5jj

WordPress before 5.2.3 allows XSS in shortcode previews.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-hmqr-j9c3-8h75

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

CVSS3: 8.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-hm6q-fjph-v26v

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script .

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-hm63-rvp6-rvmj

wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-hhj8-hj4j-7q6w

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

1%
Низкий
около 3 лет назад
github логотип
GHSA-hgh7-wggh-fw3g

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
5%
Низкий
около 3 лет назад

Уязвимостей на страницу