Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

nvd логотип

CVE-2017-17092

около 8 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-17092

около 8 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require t ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-17091

около 8 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-17091

около 8 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-17091

около 8 лет назад

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser k ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-16510

больше 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-16510

больше 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-16510

больше 8 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-14990

больше 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-14990

больше 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2017-14990

больше 8 лет назад

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14726

больше 8 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-14726

больше 8 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-14726

больше 8 лет назад

Before version 4.8.2, WordPress was vulnerable to a cross-site scripti ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-14725

больше 8 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-14725

больше 8 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-14725

больше 8 лет назад

Before version 4.8.2, WordPress was susceptible to an open redirect at ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-14724

больше 8 лет назад

Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-14724

больше 8 лет назад

Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-14724

больше 8 лет назад

Before version 4.8.2, WordPress was vulnerable to cross-site scripting ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require t ...

CVSS3: 5.4
3%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
4%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

CVSS3: 8.8
4%
Низкий
около 8 лет назад
debian логотип
CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser k ...

CVSS3: 8.8
4%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
4%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
4%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() ...

CVSS3: 9.8
4%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS3: 6.5
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but ...

CVSS3: 6.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
6%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

CVSS3: 6.1
6%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripti ...

CVSS3: 6.1
6%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
3%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVSS3: 5.4
3%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect at ...

CVSS3: 5.4
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-14724

Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

CVSS3: 6.1
8%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-14724

Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

CVSS3: 6.1
8%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-14724

Before version 4.8.2, WordPress was vulnerable to cross-site scripting ...

CVSS3: 6.1
8%
Низкий
больше 8 лет назад

Уязвимостей на страницу