Количество 1 912
Количество 1 912
CVE-2005-1688
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
CVE-2005-1688
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
CVE-2005-1688
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive ...
CVE-2005-1687
SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.
CVE-2005-1687
SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and e ...
CVE-2005-1102
Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.
CVE-2005-1102
Multiple cross-site scripting (XSS) vulnerabilities in template-functi ...
CVE-2004-1584
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
CVE-2004-1584
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows r ...
CVE-2004-1559
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.
CVE-2004-1559
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.
CVE-2004-1559
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 a ...
CVE-2003-1599
WordPress 0.7 allows remote execution of commands. / Wp-links / links.all.php. An attacker can inject a url in $ abspath and get remote execution of commands with the privileges of the server web (usually nobody).
CVE-2003-1599
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
CVE-2003-1598
WordPress 0.7 (b2 cafelog code) allows SQL injection. / Blog.header.php. $ posts not converted to an integer, so we can inject sql in this variable. In MySQL 4.x can use UNION and subselects to obtain privileges.
CVE-2003-1598
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
CVE-2003-1598
SQL injection vulnerability in log.header.php in WordPress 0.7 and ear ...
BDU:2026-10242
Уязвимость класса WP_Query системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код и получить несанкционированный доступ к конфиденциальной информации
BDU:2026-10241
Уязвимость функции get_items() системы управления содержимым сайта WordPress, позволяющая нарушителю обойти ограничения безопасности, выполнить произвольный код и получить несанкционированный доступ к защищаемой информации
BDU:2025-13139
Уязвимость системы управления содержимым сайта WordPress, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2005-1688 Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message. | CVSS3: 5.3 | 2% Низкий | около 21 года назад | |
CVE-2005-1688 Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message. | CVSS3: 5.3 | 2% Низкий | около 21 года назад | |
CVE-2005-1688 Wordpress 1.5 and earlier allows remote attackers to obtain sensitive ... | CVSS3: 5.3 | 2% Низкий | около 21 года назад | |
CVE-2005-1687 SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. | CVSS2: 7.5 | 2% Низкий | около 21 года назад | |
CVE-2005-1687 SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and e ... | CVSS2: 7.5 | 2% Низкий | около 21 года назад | |
CVE-2005-1102 Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post. | CVSS2: 6.8 | 3% Низкий | около 21 года назад | |
CVE-2005-1102 Multiple cross-site scripting (XSS) vulnerabilities in template-functi ... | CVSS2: 6.8 | 3% Низкий | около 21 года назад | |
CVE-2004-1584 CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter. | CVSS2: 5 | 11% Средний | больше 21 года назад | |
CVE-2004-1584 CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows r ... | CVSS2: 5 | 11% Средний | больше 21 года назад | |
CVE-2004-1559 Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php. | CVSS2: 4.3 | 6% Низкий | больше 21 года назад | |
CVE-2004-1559 Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php. | CVSS2: 4.3 | 6% Низкий | больше 21 года назад | |
CVE-2004-1559 Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 a ... | CVSS2: 4.3 | 6% Низкий | больше 21 года назад | |
CVE-2003-1599 WordPress 0.7 allows remote execution of commands. / Wp-links / links.all.php. An attacker can inject a url in $ abspath and get remote execution of commands with the privileges of the server web (usually nobody). | CVSS2: 7.5 | 3% Низкий | почти 12 лет назад | |
CVE-2003-1599 PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable. | CVSS2: 7.5 | 3% Низкий | почти 12 лет назад | |
CVE-2003-1598 WordPress 0.7 (b2 cafelog code) allows SQL injection. / Blog.header.php. $ posts not converted to an integer, so we can inject sql in this variable. In MySQL 4.x can use UNION and subselects to obtain privileges. | CVSS2: 7.5 | 3% Низкий | почти 12 лет назад | |
CVE-2003-1598 SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable. | CVSS2: 7.5 | 3% Низкий | почти 12 лет назад | |
CVE-2003-1598 SQL injection vulnerability in log.header.php in WordPress 0.7 and ear ... | CVSS2: 7.5 | 3% Низкий | почти 12 лет назад | |
BDU:2026-10242 Уязвимость класса WP_Query системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код и получить несанкционированный доступ к конфиденциальной информации | CVSS3: 9.1 | 16 дней назад | ||
BDU:2026-10241 Уязвимость функции get_items() системы управления содержимым сайта WordPress, позволяющая нарушителю обойти ограничения безопасности, выполнить произвольный код и получить несанкционированный доступ к защищаемой информации | CVSS3: 9.8 | 98% Критический | 16 дней назад | |
BDU:2025-13139 Уязвимость системы управления содержимым сайта WordPress, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки | CVSS3: 5.9 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу