Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

nvd логотип

CVE-2014-5240

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2014-5240

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-5205

больше 11 лет назад

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-5205

больше 11 лет назад

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-5205

больше 11 лет назад

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delim ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5204

больше 11 лет назад

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-5204

больше 11 лет назад

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-5204

больше 11 лет назад

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CS ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5203

больше 11 лет назад

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-5203

больше 11 лет назад

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-5203

больше 11 лет назад

wp-includes/class-wp-customize-widgets.php in the widget implementatio ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-0166

почти 12 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2014-0166

почти 12 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2014-0166

почти 12 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in W ...

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2014-0165

почти 12 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-0165

почти 12 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0165

почти 12 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authentica ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-7233

около 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-7233

около 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-7233

около 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the retrospam compo ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-5240

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.

CVSS2: 2.1
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-5240

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php ...

CVSS2: 2.1
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-5205

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-5205

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-5205

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delim ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-5204

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-5204

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-5204

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CS ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-5203

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

CVSS2: 7.5
7%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-5203

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

CVSS2: 7.5
7%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-5203

wp-includes/class-wp-customize-widgets.php in the widget implementatio ...

CVSS2: 7.5
7%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
32%
Средний
почти 12 лет назад
nvd логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
32%
Средний
почти 12 лет назад
debian логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in W ...

CVSS2: 6.4
32%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authentica ...

CVSS2: 4
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
1%
Низкий
около 12 лет назад
debian логотип
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam compo ...

CVSS2: 6.8
1%
Низкий
около 12 лет назад

Уязвимостей на страницу