Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

ubuntu логотип

CVE-2015-5732

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5732

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5732

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the form function in the W ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5731

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-5731

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-5731

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php i ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-5730

больше 10 лет назад

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2015-5730

больше 10 лет назад

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-5730

больше 10 лет назад

The sanitize_widget_instance function in wp-includes/class-wp-customiz ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-5715

около 10 лет назад

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5715

около 10 лет назад

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5715

около 10 лет назад

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5714

около 10 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2015-5714

около 10 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2015-5714

около 10 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 all ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-5623

почти 11 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-5623

почти 11 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-5623

почти 11 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capabil ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-5622

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-5622

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-5732

Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.

CVSS2: 4.3
8%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5732

Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.

CVSS2: 4.3
8%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5732

Cross-site scripting (XSS) vulnerability in the form function in the W ...

CVSS2: 4.3
8%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5731

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVSS2: 6.8
4%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5731

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.

CVSS2: 6.8
4%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5731

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php i ...

CVSS2: 6.8
4%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5730

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.

CVSS2: 5
8%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5730

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.

CVSS2: 5
8%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-5730

The sanitize_widget_instance function in wp-includes/class-wp-customiz ...

CVSS2: 5
8%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-5715

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

CVSS3: 4.3
6%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-5715

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

CVSS3: 4.3
6%
Низкий
около 10 лет назад
debian логотип
CVE-2015-5715

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in ...

CVSS3: 4.3
6%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-5714

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVSS3: 6.1
6%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-5714

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

CVSS3: 6.1
6%
Низкий
около 10 лет назад
debian логотип
CVE-2015-5714

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 all ...

CVSS3: 6.1
6%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
9%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
9%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capabil ...

CVSS2: 4
9%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-5622

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.

CVSS2: 3.5
5%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-5622

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.

CVSS2: 3.5
5%
Низкий
почти 11 лет назад

Уязвимостей на страницу