Количество 1 906
Количество 1 906
CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject ...
CVE-2019-17671
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVE-2019-17671
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVE-2019-17671
In WordPress before 5.2.4, unauthenticated viewing of certain content ...
CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ...
CVE-2019-17669
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVE-2019-17669
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVE-2019-17669
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ...
CVE-2019-16781
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
CVE-2019-16781
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
CVE-2019-16781
In WordPress before 5.3.1, authenticated users with lower privileges ( ...
CVE-2019-16780
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled.
CVE-2019-16780
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled.
CVE-2019-16780
WordPress users with lower privileges (like contributors) can inject J ...
CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-17672 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. | CVSS3: 6.1 | 5% Низкий | больше 6 лет назад | |
CVE-2019-17672 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. | CVSS3: 6.1 | 5% Низкий | больше 6 лет назад | |
CVE-2019-17672 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject ... | CVSS3: 6.1 | 5% Низкий | больше 6 лет назад | |
CVE-2019-17671 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | CVSS3: 5.3 | 83% Высокий | больше 6 лет назад | |
CVE-2019-17671 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | CVSS3: 5.3 | 83% Высокий | больше 6 лет назад | |
CVE-2019-17671 In WordPress before 5.2.4, unauthenticated viewing of certain content ... | CVSS3: 5.3 | 83% Высокий | больше 6 лет назад | |
CVE-2019-17670 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. | CVSS3: 9.8 | 6% Низкий | больше 6 лет назад | |
CVE-2019-17670 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. | CVSS3: 9.8 | 6% Низкий | больше 6 лет назад | |
CVE-2019-17670 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ... | CVSS3: 9.8 | 6% Низкий | больше 6 лет назад | |
CVE-2019-17669 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. | CVSS3: 9.8 | 10% Низкий | больше 6 лет назад | |
CVE-2019-17669 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. | CVSS3: 9.8 | 10% Низкий | больше 6 лет назад | |
CVE-2019-17669 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulner ... | CVSS3: 9.8 | 10% Низкий | больше 6 лет назад | |
CVE-2019-16781 In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS. | CVSS3: 5.8 | 3% Низкий | около 6 лет назад | |
CVE-2019-16781 In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS. | CVSS3: 5.8 | 3% Низкий | около 6 лет назад | |
CVE-2019-16781 In WordPress before 5.3.1, authenticated users with lower privileges ( ... | CVSS3: 5.8 | 3% Низкий | около 6 лет назад | |
CVE-2019-16780 WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled. | CVSS3: 5.8 | 4% Низкий | около 6 лет назад | |
CVE-2019-16780 WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled. | CVSS3: 5.8 | 4% Низкий | около 6 лет назад | |
CVE-2019-16780 WordPress users with lower privileges (like contributors) can inject J ... | CVSS3: 5.8 | 4% Низкий | около 6 лет назад | |
CVE-2019-16223 WordPress before 5.2.3 allows XSS in post previews by authenticated users. | CVSS3: 5.4 | 4% Низкий | больше 6 лет назад | |
CVE-2019-16223 WordPress before 5.2.3 allows XSS in post previews by authenticated users. | CVSS3: 5.4 | 4% Низкий | больше 6 лет назад |
Уязвимостей на страницу