Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

debian логотип

CVE-2014-9036

около 11 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3. ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9035

около 11 лет назад

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9035

около 11 лет назад

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9035

около 11 лет назад

Cross-site scripting (XSS) vulnerability in Press This in WordPress be ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9034

около 11 лет назад

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
EPSS: Высокий
nvd логотип

CVE-2014-9034

около 11 лет назад

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2014-9034

около 11 лет назад

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3 ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2014-9033

около 11 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-9033

около 11 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-9033

около 11 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-login.php in Wor ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9032

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9032

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9032

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the media-playlists featur ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9031

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9031

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9031

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the wptexturize function i ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-6412

почти 8 лет назад

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2014-6412

почти 8 лет назад

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2014-6412

почти 8 лет назад

WordPress before 4.4 makes it easier for remote attackers to predict p ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2014-5240

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2014-9036

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3. ...

CVSS2: 4.3
1%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-9035

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9035

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9035

Cross-site scripting (XSS) vulnerability in Press This in WordPress be ...

CVSS2: 4.3
1%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-9034

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
72%
Высокий
около 11 лет назад
nvd логотип
CVE-2014-9034

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
72%
Высокий
около 11 лет назад
debian логотип
CVE-2014-9034

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3 ...

CVSS2: 5
72%
Высокий
около 11 лет назад
ubuntu логотип
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
1%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in Wor ...

CVSS2: 6.8
1%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-9032

Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9032

Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9032

Cross-site scripting (XSS) vulnerability in the media-playlists featur ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-9031

Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9031

Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9031

Cross-site scripting (XSS) vulnerability in the wptexturize function i ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-6412

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 8.1
2%
Низкий
почти 8 лет назад
nvd логотип
CVE-2014-6412

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 8.1
2%
Низкий
почти 8 лет назад
debian логотип
CVE-2014-6412

WordPress before 4.4 makes it easier for remote attackers to predict p ...

CVSS3: 8.1
2%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2014-5240

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.

CVSS2: 2.1
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу