Количество 1 894
Количество 1 894
GHSA-93gm-xcwj-q3j2
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
GHSA-9354-f967-7fw8
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
GHSA-92h3-fjv6-rmmc
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
GHSA-928v-37ff-2cvr
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
GHSA-8xjm-q43j-6v96
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
GHSA-8wqr-ch99-7r8g
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).
GHSA-8rwr-ffp6-2577
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
GHSA-8rr8-9498-4v45
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.
GHSA-8rmg-wmq4-q93v
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
GHSA-8p43-h625-cvh5
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
GHSA-8j68-mq56-8vpm
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
GHSA-8ggp-4pf2-5mgh
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
GHSA-8fxj-85rv-jj93
WordPress before 5.2.3 allows reflected XSS in the dashboard.
GHSA-8chx-6qqw-75xx
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.
GHSA-8cg5-rjxh-5v62
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.
GHSA-8c9g-j366-5fcx
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
GHSA-893q-vmc7-qcvh
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
GHSA-86pg-877h-rfr2
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
GHSA-8688-jv8f-2mcf
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
GHSA-8292-xqwp-qw46
Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-93gm-xcwj-q3j2 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. | CVSS3: 7.5 | 4% Низкий | около 3 лет назад | |
GHSA-9354-f967-7fw8 WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source. | 1% Низкий | больше 3 лет назад | ||
GHSA-92h3-fjv6-rmmc Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags. | CVSS3: 6.1 | 29% Средний | около 3 лет назад | |
GHSA-928v-37ff-2cvr Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php. | CVSS3: 5.4 | 5% Низкий | около 3 лет назад | |
GHSA-8xjm-q43j-6v96 wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter. | 1% Низкий | около 3 лет назад | ||
GHSA-8wqr-ch99-7r8g Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable). | 1% Низкий | больше 3 лет назад | ||
GHSA-8rwr-ffp6-2577 wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message. | 2% Низкий | около 3 лет назад | ||
GHSA-8rr8-9498-4v45 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes. | 1% Низкий | около 3 лет назад | ||
GHSA-8rmg-wmq4-q93v Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components. | CVSS3: 7.5 | 48% Средний | около 3 лет назад | |
GHSA-8p43-h625-cvh5 Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors. | 2% Низкий | около 3 лет назад | ||
GHSA-8j68-mq56-8vpm wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring. | CVSS3: 9.8 | 3% Низкий | около 3 лет назад | |
GHSA-8ggp-4pf2-5mgh In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public. | 0% Низкий | около 3 лет назад | ||
GHSA-8fxj-85rv-jj93 WordPress before 5.2.3 allows reflected XSS in the dashboard. | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-8chx-6qqw-75xx In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename. | CVSS3: 6.1 | 2% Низкий | около 3 лет назад | |
GHSA-8cg5-rjxh-5v62 WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. | 0% Низкий | около 3 лет назад | ||
GHSA-8c9g-j366-5fcx In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session. | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-893q-vmc7-qcvh The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors. | CVSS3: 7.5 | 2% Низкий | около 3 лет назад | |
GHSA-86pg-877h-rfr2 WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-8688-jv8f-2mcf WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors. | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-8292-xqwp-qw46 Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php. | 4% Низкий | больше 3 лет назад |
Уязвимостей на страницу