Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

ubuntu логотип

CVE-2017-5487

больше 8 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
EPSS: Критический
nvd логотип

CVE-2017-5487

больше 8 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
EPSS: Критический
debian логотип

CVE-2017-5487

больше 8 лет назад

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
EPSS: Критический
ubuntu логотип

CVE-2017-17094

больше 7 лет назад

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-17094

больше 7 лет назад

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17094

больше 7 лет назад

wp-includes/feed.php in WordPress before 4.9.1 does not properly restr ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17093

больше 7 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-17093

больше 7 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17093

больше 7 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not pr ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17092

больше 7 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-17092

больше 7 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17092

больше 7 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require t ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17091

больше 7 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-17091

больше 7 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-17091

больше 7 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser k ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-16510

почти 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-16510

почти 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-16510

почти 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-14990

почти 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-14990

почти 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
92%
Критический
больше 8 лет назад
nvd логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

CVSS3: 5.3
92%
Критический
больше 8 лет назад
debian логотип
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in t ...

CVSS3: 5.3
92%
Критический
больше 8 лет назад
ubuntu логотип
CVE-2017-17094

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
4%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-17094

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

CVSS3: 5.4
4%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-17094

wp-includes/feed.php in WordPress before 4.9.1 does not properly restr ...

CVSS3: 5.4
4%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
5%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
5%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not pr ...

CVSS3: 5.4
5%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require t ...

CVSS3: 5.4
2%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
5%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
5%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser k ...

CVSS3: 8.8
5%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
4%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
4%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
4%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
1%
Низкий
почти 8 лет назад

Уязвимостей на страницу