Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

debian логотип

CVE-2016-5838

около 9 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended pass ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-5837

около 9 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5837

около 9 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5837

около 9 лет назад

WordPress before 4.5.3 allows remote attackers to bypass intended acce ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-5836

около 9 лет назад

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5836

около 9 лет назад

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5836

около 9 лет назад

The oEmbed protocol implementation in WordPress before 4.5.3 allows re ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-5835

около 9 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5835

около 9 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5835

около 9 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive rev ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-5834

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5834

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5834

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-5833

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5833

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5833

около 9 лет назад

Cross-site scripting (XSS) vulnerability in the column_title function ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-5832

около 9 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5832

около 9 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5832

около 9 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to by ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4029

около 9 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2016-5838

WordPress before 4.5.3 allows remote attackers to bypass intended pass ...

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5837

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5837

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5837

WordPress before 4.5.3 allows remote attackers to bypass intended acce ...

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5836

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
5%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5836

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
5%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5836

The oEmbed protocol implementation in WordPress before 4.5.3 allows re ...

CVSS3: 7.5
5%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive rev ...

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5834

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5834

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5834

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link ...

CVSS3: 6.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function ...

CVSS3: 6.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5832

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5832

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5832

The customizer in WordPress before 4.5.3 allows remote attackers to by ...

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
0%
Низкий
около 9 лет назад

Уязвимостей на страницу