Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

ubuntu логотип

CVE-2020-28035

больше 5 лет назад

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-28035

больше 5 лет назад

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-28035

больше 5 лет назад

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2020-28034

больше 5 лет назад

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-28034

больше 5 лет назад

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-28034

больше 5 лет назад

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-28033

больше 5 лет назад

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-28033

больше 5 лет назад

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-28033

больше 5 лет назад

WordPress before 5.5.2 mishandles embeds from disabled sites on a mult ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-28032

больше 5 лет назад

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2020-28032

больше 5 лет назад

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2020-28032

больше 5 лет назад

WordPress before 5.5.2 mishandles deserialization requests in wp-inclu ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2020-25286

больше 5 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25286

больше 5 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25286

больше 5 лет назад

In wp-includes/comment-template.php in WordPress before 5.4.2, comment ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-11030

почти 6 лет назад

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2020-11030

почти 6 лет назад

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2020-11030

почти 6 лет назад

In affected versions of WordPress, a special payload can be crafted th ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2020-11029

почти 6 лет назад

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2020-11029

почти 6 лет назад

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-28035

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
5%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-28035

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

CVSS3: 9.8
5%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-28035

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC ...

CVSS3: 9.8
5%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-28034

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
3%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-28034

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
3%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-28034

WordPress before 5.5.2 allows XSS associated with global variables.

CVSS3: 6.1
3%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-28033

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-28033

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-28033

WordPress before 5.5.2 mishandles embeds from disabled sites on a mult ...

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-28032

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
26%
Средний
больше 5 лет назад
nvd логотип
CVE-2020-28032

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVSS3: 9.8
26%
Средний
больше 5 лет назад
debian логотип
CVE-2020-28032

WordPress before 5.5.2 mishandles deserialization requests in wp-inclu ...

CVSS3: 9.8
26%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2020-25286

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-25286

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-25286

In wp-includes/comment-template.php in WordPress before 5.4.2, comment ...

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-11030

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 6.4
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-11030

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 6.4
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-11030

In affected versions of WordPress, a special payload can be crafted th ...

CVSS3: 6.4
1%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-11029

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 5.8
3%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-11029

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVSS3: 5.8
3%
Низкий
почти 6 лет назад

Уязвимостей на страницу