Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

ubuntu логотип

CVE-2016-4567

около 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-4567

около 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-4567

около 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-4566

около 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-4566

около 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-4566

около 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plup ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-3429

около 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3429

около 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3429

около 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-5266

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
EPSS: Высокий
nvd логотип

CVE-2014-5266

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2014-5266

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2014-5265

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-5265

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-5265

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-4603

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-4600

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-4534

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-4529

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-3845

около 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
5%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
5%
Низкий
около 9 лет назад
debian логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as ...

CVSS3: 6.1
5%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
6%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
6%
Низкий
около 9 лет назад
debian логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plup ...

CVSS3: 6.1
6%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
2%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons ...

CVSS2: 4.3
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2014-5266

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
77%
Высокий
почти 11 лет назад
nvd логотип
CVE-2014-5266

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
77%
Высокий
почти 11 лет назад
debian логотип
CVE-2014-5266

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
77%
Высокий
почти 11 лет назад
ubuntu логотип
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
7%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-4603

Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-4600

Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-4534

Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-4529

Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-3845

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information.

CVSS2: 6.8
0%
Низкий
около 11 лет назад

Уязвимостей на страницу