Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

nvd логотип

CVE-2011-3125

около 14 лет назад

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-3125

около 14 лет назад

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-3122

около 14 лет назад

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-3122

около 14 лет назад

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-3122

около 14 лет назад

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-1762

больше 3 лет назад

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2011-1762

больше 3 лет назад

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2011-1762

больше 3 лет назад

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'sc ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-0701

больше 14 лет назад

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-0701

больше 14 лет назад

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-0701

больше 14 лет назад

wp-admin/async-upload.php in the media uploader in WordPress before 3. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-0700

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2011-0700

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2011-0700

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-5297

больше 11 лет назад

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2010-5297

больше 11 лет назад

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2010-5297

больше 11 лет назад

WordPress before 3.0.1, when a Multisite installation is used, permane ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2010-5296

больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2010-5296

больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2010-5296

больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-3125

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."

CVSS2: 10
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3125

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before ...

CVSS2: 10
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3122

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

CVSS2: 10
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3122

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

CVSS2: 10
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3122

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before ...

CVSS2: 10
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'sc ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2011-0701

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-0701

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-0701

wp-admin/async-upload.php in the media uploader in WordPress before 3. ...

CVSS2: 4
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-0700

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-0700

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-0700

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 3.5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-5297

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5297

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5297

WordPress before 3.0.1, when a Multisite installation is used, permane ...

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

CVSS2: 4.9
0%
Низкий
больше 11 лет назад

Уязвимостей на страницу