Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 896

Количество 1 896

github логотип

GHSA-2gwv-7wq2-wv5g

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2gph-8pg4-626q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

EPSS: Низкий
github логотип

GHSA-2cv7-399j-p9vv

больше 3 лет назад

SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-277w-qpxr-2549

больше 3 лет назад

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26p6-3rqx-jxq4

больше 3 лет назад

Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-269q-phhx-gq68

больше 3 лет назад

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

EPSS: Низкий
github логотип

GHSA-25w3-g886-5v8g

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter.

EPSS: Низкий
github логотип

GHSA-23m7-7w92-xgf9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

EPSS: Низкий
ubuntu логотип

CVE-2023-38000

около 2 лет назад

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-38000

около 2 лет назад

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-38000

около 2 лет назад

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability i ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-36326

больше 4 лет назад

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-36326

больше 4 лет назад

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-36326

больше 4 лет назад

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Des ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-26596

около 5 лет назад

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2018-19296

почти 7 лет назад

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-19296

почти 7 лет назад

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-19296

почти 7 лет назад

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an objec ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-5611

почти 9 лет назад

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2017-5611

почти 9 лет назад

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gwv-7wq2-wv5g

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gph-8pg4-626q

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cv7-399j-p9vv

SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-277w-qpxr-2549

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
4%
Низкий
больше 3 лет назад
github логотип
GHSA-26p6-3rqx-jxq4

Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-269q-phhx-gq68

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-25w3-g886-5v8g

Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23m7-7w92-xgf9

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2023-38000

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-38000

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-38000

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability i ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Des ...

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-26596

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

CVSS3: 8.8
17%
Средний
около 5 лет назад
ubuntu логотип
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an objec ...

CVSS3: 8.8
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2017-5611

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
12%
Средний
почти 9 лет назад
nvd логотип
CVE-2017-5611

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
12%
Средний
почти 9 лет назад

Уязвимостей на страницу