Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

debian логотип

CVE-2014-5203

почти 11 лет назад

wp-includes/class-wp-customize-widgets.php in the widget implementatio ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-0166

больше 11 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2014-0166

больше 11 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2014-0166

больше 11 лет назад

The wp_validate_auth_cookie function in wp-includes/pluggable.php in W ...

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2014-0165

больше 11 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-0165

больше 11 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0165

больше 11 лет назад

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authentica ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-7233

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-7233

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-7233

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the retrospam compo ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-5739

почти 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-5739

почти 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-5739

почти 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent u ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-5738

почти 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5738

почти 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-5738

почти 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in Wo ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-4340

почти 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-4340

почти 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4340

почти 12 лет назад

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4339

почти 12 лет назад

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2014-5203

wp-includes/class-wp-customize-widgets.php in the widget implementatio ...

CVSS2: 7.5
4%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
35%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.

CVSS2: 6.4
35%
Средний
больше 11 лет назад
debian логотип
CVE-2014-0166

The wp_validate_auth_cookie function in wp-includes/pluggable.php in W ...

CVSS2: 6.4
35%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

CVSS2: 4
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0165

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authentica ...

CVSS2: 4
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam compo ...

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS2: 3.5
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent u ...

CVSS2: 3.5
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

CVSS2: 4.3
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-5738

The get_allowed_mime_types function in wp-includes/functions.php in Wo ...

CVSS2: 4.3
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

CVSS2: 3.5
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-4340

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...

CVSS2: 3.5
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-4339

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

CVSS2: 7.5
1%
Низкий
почти 12 лет назад

Уязвимостей на страницу