Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

ubuntu логотип

CVE-2017-17093

больше 8 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-17093

больше 8 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17093

больше 8 лет назад

wp-includes/general-template.php in WordPress before 4.9.1 does not pr ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17092

больше 8 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-17092

больше 8 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17092

больше 8 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require t ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17091

больше 8 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-17091

больше 8 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-17091

больше 8 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser k ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-16510

больше 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-16510

больше 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-16510

больше 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-14990

почти 9 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-14990

почти 9 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2017-14990

почти 9 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14726

почти 9 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-14726

почти 9 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-14726

почти 9 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripti ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-14725

почти 9 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-14725

почти 9 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
2%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

CVSS3: 5.4
2%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not pr ...

CVSS3: 5.4
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
4%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
4%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require t ...

CVSS3: 5.4
4%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
8%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
8%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser k ...

CVSS3: 8.8
8%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
8%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
8%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
8%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
2%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but ...

CVSS3: 6.5
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
3%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
3%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripti ...

CVSS3: 6.1
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
2%
Низкий
почти 9 лет назад

Уязвимостей на страницу