Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

ubuntu логотип

CVE-2017-6814

почти 9 лет назад

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-6814

почти 9 лет назад

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-6814

почти 9 лет назад

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-6514

больше 6 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-6514

больше 6 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-6514

больше 6 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remo ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-5612

около 9 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5612

около 9 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5612

около 9 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-5610

около 9 лет назад

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-5610

около 9 лет назад

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-5610

около 9 лет назад

wp-admin/includes/class-wp-press-this.php in Press This in WordPress b ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-5493

около 9 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-5493

около 9 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-5493

около 9 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPre ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-5492

около 9 лет назад

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-5492

около 9 лет назад

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-5492

около 9 лет назад

Cross-site request forgery (CSRF) vulnerability in the widget-editing ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-5491

около 9 лет назад

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-5491

около 9 лет назад

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
2%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting ...

CVSS3: 5.4
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remo ...

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2017-5612

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
2%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5612

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
2%
Низкий
около 9 лет назад
debian логотип
CVE-2017-5612

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp ...

CVSS3: 6.1
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5610

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5610

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
1%
Низкий
около 9 лет назад
debian логотип
CVE-2017-5610

wp-admin/includes/class-wp-press-this.php in Press This in WordPress b ...

CVSS3: 5.3
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
debian логотип
CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPre ...

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5492

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5492

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
debian логотип
CVE-2017-5492

Cross-site request forgery (CSRF) vulnerability in the widget-editing ...

CVSS3: 8.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5491

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

CVSS3: 5.3
2%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5491

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

CVSS3: 5.3
2%
Низкий
около 9 лет назад

Уязвимостей на страницу