Количество 1 906
Количество 1 906
CVE-2015-5731
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.
CVE-2015-5731
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php i ...
CVE-2015-5730
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
CVE-2015-5730
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
CVE-2015-5730
The sanitize_widget_instance function in wp-includes/class-wp-customiz ...
CVE-2015-5715
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
CVE-2015-5715
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
CVE-2015-5715
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in ...
CVE-2015-5714
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
CVE-2015-5714
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
CVE-2015-5714
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 all ...
CVE-2015-5623
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
CVE-2015-5623
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
CVE-2015-5623
WordPress before 4.2.3 does not properly verify the edit_posts capabil ...
CVE-2015-5622
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.
CVE-2015-5622
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.
CVE-2015-5622
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 all ...
CVE-2015-3440
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.
CVE-2015-3440
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.
CVE-2015-3440
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in W ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2015-5731 Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action. | CVSS2: 6.8 | 15% Средний | около 10 лет назад | |
CVE-2015-5731 Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php i ... | CVSS2: 6.8 | 15% Средний | около 10 лет назад | |
CVE-2015-5730 The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated. | CVSS2: 5 | 10% Низкий | около 10 лет назад | |
CVE-2015-5730 The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated. | CVSS2: 5 | 10% Низкий | около 10 лет назад | |
CVE-2015-5730 The sanitize_widget_instance function in wp-includes/class-wp-customiz ... | CVSS2: 5 | 10% Низкий | около 10 лет назад | |
CVE-2015-5715 The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors. | CVSS3: 4.3 | 29% Средний | больше 9 лет назад | |
CVE-2015-5715 The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors. | CVSS3: 4.3 | 29% Средний | больше 9 лет назад | |
CVE-2015-5715 The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in ... | CVSS3: 4.3 | 29% Средний | больше 9 лет назад | |
CVE-2015-5714 Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags. | CVSS3: 6.1 | 31% Средний | больше 9 лет назад | |
CVE-2015-5714 Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags. | CVSS3: 6.1 | 31% Средний | больше 9 лет назад | |
CVE-2015-5714 Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 all ... | CVSS3: 6.1 | 31% Средний | больше 9 лет назад | |
CVE-2015-5623 WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php. | CVSS2: 4 | 48% Средний | больше 10 лет назад | |
CVE-2015-5623 WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php. | CVSS2: 4 | 48% Средний | больше 10 лет назад | |
CVE-2015-5623 WordPress before 4.2.3 does not properly verify the edit_posts capabil ... | CVSS2: 4 | 48% Средний | больше 10 лет назад | |
CVE-2015-5622 Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php. | CVSS2: 3.5 | 1% Низкий | больше 10 лет назад | |
CVE-2015-5622 Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php. | CVSS2: 3.5 | 1% Низкий | больше 10 лет назад | |
CVE-2015-5622 Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 all ... | CVSS2: 3.5 | 1% Низкий | больше 10 лет назад | |
CVE-2015-3440 Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. | CVSS2: 4.3 | 10% Средний | больше 10 лет назад | |
CVE-2015-3440 Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. | CVSS2: 4.3 | 10% Средний | больше 10 лет назад | |
CVE-2015-3440 Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in W ... | CVSS2: 4.3 | 10% Средний | больше 10 лет назад |
Уязвимостей на страницу