Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

nvd логотип

CVE-2018-6389

почти 8 лет назад

In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

CVSS3: 7.5
EPSS: Высокий
debian логотип

CVE-2018-6389

почти 8 лет назад

In WordPress through 4.9.2, unauthenticated attackers can cause a deni ...

CVSS3: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2018-5776

около 8 лет назад

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-5776

около 8 лет назад

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-5776

около 8 лет назад

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaEle ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-20153

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-20153

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-20153

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-20152

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2018-20152

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2018-20152

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass i ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2018-20151

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-20151

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-20151

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation pa ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2018-20150

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-20150

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-20150

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could tri ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-20149

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-20149

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-20149

около 7 лет назад

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP S ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-6389

In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

CVSS3: 7.5
87%
Высокий
почти 8 лет назад
debian логотип
CVE-2018-6389

In WordPress through 4.9.2, unauthenticated attackers can cause a deni ...

CVSS3: 7.5
87%
Высокий
почти 8 лет назад
ubuntu логотип
CVE-2018-5776

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5776

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
3%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5776

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaEle ...

CVSS3: 6.1
3%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
5%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

CVSS3: 5.4
5%
Низкий
около 7 лет назад
debian логотип
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could mod ...

CVSS3: 5.4
5%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
12%
Средний
около 7 лет назад
nvd логотип
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

CVSS3: 6.5
12%
Средний
около 7 лет назад
debian логотип
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass i ...

CVSS3: 6.5
12%
Средний
около 7 лет назад
ubuntu логотип
CVE-2018-20151

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
7%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-20151

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.

CVSS3: 7.5
7%
Низкий
около 7 лет назад
debian логотип
CVE-2018-20151

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation pa ...

CVSS3: 7.5
7%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-20150

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
7%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-20150

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

CVSS3: 6.1
7%
Низкий
около 7 лет назад
debian логотип
CVE-2018-20150

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could tri ...

CVSS3: 6.1
7%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-20149

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
4%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-20149

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

CVSS3: 5.4
4%
Низкий
около 7 лет назад
debian логотип
CVE-2018-20149

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP S ...

CVSS3: 5.4
4%
Низкий
около 7 лет назад

Уязвимостей на страницу