Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

debian логотип

CVE-2017-5491

около 9 лет назад

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-5490

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5490

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5490

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-5489

около 9 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-5489

около 9 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-5489

около 9 лет назад

Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-5488

около 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5488

около 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5488

около 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-5487

около 9 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
EPSS: Критический
nvd логотип

CVE-2017-5487

около 9 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
EPSS: Критический
debian логотип

CVE-2017-5487

около 9 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
EPSS: Критический
ubuntu логотип

CVE-2017-17094

около 8 лет назад

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-17094

около 8 лет назад

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17094

около 8 лет назад

wp-includes/feed.php in WordPress before 4.9.1 does not properly restr ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17093

около 8 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-17093

около 8 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17093

около 8 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not pr ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17092

около 8 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2017-5491

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to ...

CVSS3: 5.3
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
debian логотип
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback fu ...

CVSS3: 6.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
debian логотип
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4. ...

CVSS3: 8.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
debian логотип
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update ...

CVSS3: 6.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
92%
Критический
около 9 лет назад
nvd логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
92%
Критический
около 9 лет назад
debian логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
92%
Критический
около 9 лет назад
ubuntu логотип
CVE-2017-17094

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
7%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-17094

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
7%
Низкий
около 8 лет назад
debian логотип
CVE-2017-17094

wp-includes/feed.php in WordPress before 4.9.1 does not properly restr ...

CVSS3: 5.4
7%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
6%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
6%
Низкий
около 8 лет назад
debian логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not pr ...

CVSS3: 5.4
6%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
3%
Низкий
около 8 лет назад

Уязвимостей на страницу