Количество 1 894
Количество 1 894

CVE-2019-16219
WordPress before 5.2.3 allows XSS in shortcode previews.

CVE-2019-16219
WordPress before 5.2.3 allows XSS in shortcode previews.
CVE-2019-16219
WordPress before 5.2.3 allows XSS in shortcode previews.

CVE-2019-16218
WordPress before 5.2.3 allows XSS in stored comments.

CVE-2019-16218
WordPress before 5.2.3 allows XSS in stored comments.
CVE-2019-16218
WordPress before 5.2.3 allows XSS in stored comments.

CVE-2019-16217
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.

CVE-2019-16217
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
CVE-2019-16217
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upl ...

CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a deni ...

CVE-2018-5776
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVE-2018-5776
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
CVE-2018-5776
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaEle ...

CVE-2018-20153
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVE-2018-20153
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
CVE-2018-20153
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ...

CVE-2018-20152
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVE-2018-20152
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2019-16219 WordPress before 5.2.3 allows XSS in shortcode previews. | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад |
![]() | CVE-2019-16219 WordPress before 5.2.3 allows XSS in shortcode previews. | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад |
CVE-2019-16219 WordPress before 5.2.3 allows XSS in shortcode previews. | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад | |
![]() | CVE-2019-16218 WordPress before 5.2.3 allows XSS in stored comments. | CVSS3: 6.1 | 1% Низкий | почти 6 лет назад |
![]() | CVE-2019-16218 WordPress before 5.2.3 allows XSS in stored comments. | CVSS3: 6.1 | 1% Низкий | почти 6 лет назад |
CVE-2019-16218 WordPress before 5.2.3 allows XSS in stored comments. | CVSS3: 6.1 | 1% Низкий | почти 6 лет назад | |
![]() | CVE-2019-16217 WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад |
![]() | CVE-2019-16217 WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад |
CVE-2019-16217 WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upl ... | CVSS3: 6.1 | 2% Низкий | почти 6 лет назад | |
![]() | CVE-2018-6389 In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times. | CVSS3: 7.5 | 88% Высокий | больше 7 лет назад |
![]() | CVE-2018-6389 In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times. | CVSS3: 7.5 | 88% Высокий | больше 7 лет назад |
CVE-2018-6389 In WordPress through 4.9.2, unauthenticated attackers can cause a deni ... | CVSS3: 7.5 | 88% Высокий | больше 7 лет назад | |
![]() | CVE-2018-5776 WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). | CVSS3: 6.1 | 2% Низкий | больше 7 лет назад |
![]() | CVE-2018-5776 WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). | CVSS3: 6.1 | 2% Низкий | больше 7 лет назад |
CVE-2018-5776 WordPress before 4.9.2 has XSS in the Flash fallback files in MediaEle ... | CVSS3: 6.1 | 2% Низкий | больше 7 лет назад | |
![]() | CVE-2018-20153 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. | CVSS3: 5.4 | 4% Низкий | больше 6 лет назад |
![]() | CVE-2018-20153 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. | CVSS3: 5.4 | 4% Низкий | больше 6 лет назад |
CVE-2018-20153 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ... | CVSS3: 5.4 | 4% Низкий | больше 6 лет назад | |
![]() | CVE-2018-20152 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input. | CVSS3: 6.5 | 11% Средний | больше 6 лет назад |
![]() | CVE-2018-20152 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input. | CVSS3: 6.5 | 11% Средний | больше 6 лет назад |
Уязвимостей на страницу