Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

debian логотип

CVE-2012-6634

больше 11 лет назад

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-6633

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-6633

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-6633

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5868

больше 12 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-5868

больше 12 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2012-5868

больше 12 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upo ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-4448

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-4448

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-4448

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-4422

почти 13 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-4422

почти 13 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-4422

почти 13 лет назад

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4421

почти 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-4421

почти 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-4421

почти 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-3385

около 13 лет назад

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3385

около 13 лет назад

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3385

около 13 лет назад

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3384

около 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...

CVSS2: 6.4
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2012-5868

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-5868

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-5868

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upo ...

CVSS2: 2.6
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php ...

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-4422

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ...

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-4421

The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVSS2: 5
1%
Низкий
около 13 лет назад
debian логотип
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post conte ...

CVSS2: 5
1%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
0%
Низкий
около 13 лет назад

Уязвимостей на страницу