Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

debian логотип

CVE-2013-2203

больше 12 лет назад

WordPress before 3.5.2, when the uploads directory forbids write acces ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2202

больше 12 лет назад

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2202

больше 12 лет назад

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2202

больше 12 лет назад

WordPress before 3.5.2 allows remote attackers to read arbitrary files ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2201

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2201

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2201

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2200

больше 12 лет назад

WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-2200

больше 12 лет назад

WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-2200

больше 12 лет назад

WordPress before 3.5.2 does not properly check the capabilities of rol ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-2199

больше 12 лет назад

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2199

больше 12 лет назад

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2199

больше 12 лет назад

The HTTP API in WordPress before 3.5.2 allows remote attackers to send ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2173

больше 12 лет назад

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2173

больше 12 лет назад

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2173

больше 12 лет назад

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-prote ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-0236

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0236

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-0236

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-0235

больше 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2013-2203

WordPress before 3.5.2, when the uploads directory forbids write acces ...

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2202

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2202

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2202

WordPress before 3.5.2 allows remote attackers to read arbitrary files ...

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2201

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2201

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2201

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2200

WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.

CVSS2: 4
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2200

WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.

CVSS2: 4
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2200

WordPress before 3.5.2 does not properly check the capabilities of rol ...

CVSS2: 4
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2199

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2199

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2199

The HTTP API in WordPress before 3.5.2 allows remote attackers to send ...

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2173

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2173

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2173

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-prote ...

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-0236

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0236

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-0236

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-0235

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
65%
Средний
больше 12 лет назад

Уязвимостей на страницу