Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

debian логотип

CVE-2023-38000

больше 2 лет назад

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability i ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-36326

почти 5 лет назад

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-36326

почти 5 лет назад

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-36326

почти 5 лет назад

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Des ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-26596

больше 5 лет назад

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2018-19296

около 7 лет назад

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-19296

около 7 лет назад

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-19296

около 7 лет назад

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an objec ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-5611

около 9 лет назад

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2017-5611

около 9 лет назад

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2017-5611

около 9 лет назад

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Qu ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2016-4567

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-4567

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-4567

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-4566

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-4566

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-4566

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plup ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-3429

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3429

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3429

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-38000

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability i ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS3: 9.8
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Des ...

CVSS3: 9.8
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-26596

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.

CVSS3: 8.8
17%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

CVSS3: 8.8
1%
Низкий
около 7 лет назад
debian логотип
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an objec ...

CVSS3: 8.8
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2017-5611

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
12%
Средний
около 9 лет назад
nvd логотип
CVE-2017-5611

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS3: 9.8
12%
Средний
около 9 лет назад
debian логотип
CVE-2017-5611

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Qu ...

CVSS3: 9.8
12%
Средний
около 9 лет назад
ubuntu логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
4%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS3: 6.1
4%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-4567

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as ...

CVSS3: 6.1
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
5%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

CVSS3: 6.1
5%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-4566

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plup ...

CVSS3: 6.1
5%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3429

Cross-site scripting (XSS) vulnerability in example.html in Genericons ...

CVSS2: 4.3
2%
Низкий
больше 10 лет назад

Уязвимостей на страницу