Количество 1 894
Количество 1 894

CVE-2015-5734
Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.

CVE-2015-5734
Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.
CVE-2015-5734
Cross-site scripting (XSS) vulnerability in the legacy theme preview i ...

CVE-2015-5733
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.

CVE-2015-5733
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.
CVE-2015-5733
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessi ...

CVE-2015-5732
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.

CVE-2015-5732
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.
CVE-2015-5732
Cross-site scripting (XSS) vulnerability in the form function in the W ...

CVE-2015-5731
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVE-2015-5731
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.
CVE-2015-5731
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php i ...

CVE-2015-5730
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.

CVE-2015-5730
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
CVE-2015-5730
The sanitize_widget_instance function in wp-includes/class-wp-customiz ...

CVE-2015-5715
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

CVE-2015-5715
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
CVE-2015-5715
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in ...

CVE-2015-5714
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVE-2015-5714
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2015-5734 Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string. | CVSS2: 4.3 | 3% Низкий | почти 10 лет назад |
![]() | CVE-2015-5734 Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string. | CVSS2: 4.3 | 3% Низкий | почти 10 лет назад |
CVE-2015-5734 Cross-site scripting (XSS) vulnerability in the legacy theme preview i ... | CVSS2: 4.3 | 3% Низкий | почти 10 лет назад | |
![]() | CVE-2015-5733 Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title. | CVSS2: 4.3 | 2% Низкий | почти 10 лет назад |
![]() | CVE-2015-5733 Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title. | CVSS2: 4.3 | 2% Низкий | почти 10 лет назад |
CVE-2015-5733 Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessi ... | CVSS2: 4.3 | 2% Низкий | почти 10 лет назад | |
![]() | CVE-2015-5732 Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title. | CVSS2: 4.3 | 2% Низкий | почти 10 лет назад |
![]() | CVE-2015-5732 Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title. | CVSS2: 4.3 | 2% Низкий | почти 10 лет назад |
CVE-2015-5732 Cross-site scripting (XSS) vulnerability in the form function in the W ... | CVSS2: 4.3 | 2% Низкий | почти 10 лет назад | |
![]() | CVE-2015-5731 Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action. | CVSS2: 6.8 | 17% Средний | почти 10 лет назад |
![]() | CVE-2015-5731 Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action. | CVSS2: 6.8 | 17% Средний | почти 10 лет назад |
CVE-2015-5731 Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php i ... | CVSS2: 6.8 | 17% Средний | почти 10 лет назад | |
![]() | CVE-2015-5730 The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated. | CVSS2: 5 | 10% Средний | почти 10 лет назад |
![]() | CVE-2015-5730 The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated. | CVSS2: 5 | 10% Средний | почти 10 лет назад |
CVE-2015-5730 The sanitize_widget_instance function in wp-includes/class-wp-customiz ... | CVSS2: 5 | 10% Средний | почти 10 лет назад | |
![]() | CVE-2015-5715 The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors. | CVSS3: 4.3 | 25% Средний | около 9 лет назад |
![]() | CVE-2015-5715 The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors. | CVSS3: 4.3 | 25% Средний | около 9 лет назад |
CVE-2015-5715 The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in ... | CVSS3: 4.3 | 25% Средний | около 9 лет назад | |
![]() | CVE-2015-5714 Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags. | CVSS3: 6.1 | 29% Средний | около 9 лет назад |
![]() | CVE-2015-5714 Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags. | CVSS3: 6.1 | 29% Средний | около 9 лет назад |
Уязвимостей на страницу