Количество 1 912
Количество 1 912
CVE-2011-1762
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
CVE-2011-1762
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'sc ...
CVE-2011-0701
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
CVE-2011-0701
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
CVE-2011-0701
wp-admin/async-upload.php in the media uploader in WordPress before 3. ...
CVE-2011-0700
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
CVE-2011-0700
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
CVE-2011-0700
Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...
CVE-2010-5297
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.
CVE-2010-5297
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.
CVE-2010-5297
WordPress before 3.0.1, when a Multisite installation is used, permane ...
CVE-2010-5296
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
CVE-2010-5296
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
CVE-2010-5296
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...
CVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
CVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
CVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...
CVE-2010-5294
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
CVE-2010-5294
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
CVE-2010-5294
Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2011-1762 A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2011-1762 A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'sc ... | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2011-0701 wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter. | CVSS2: 4 | 3% Низкий | больше 15 лет назад | |
CVE-2011-0701 wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter. | CVSS2: 4 | 3% Низкий | больше 15 лет назад | |
CVE-2011-0701 wp-admin/async-upload.php in the media uploader in WordPress before 3. ... | CVSS2: 4 | 3% Низкий | больше 15 лет назад | |
CVE-2011-0700 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box. | CVSS2: 3.5 | 3% Низкий | больше 15 лет назад | |
CVE-2011-0700 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box. | CVSS2: 3.5 | 3% Низкий | больше 15 лет назад | |
CVE-2011-0700 Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ... | CVSS2: 3.5 | 3% Низкий | больше 15 лет назад | |
CVE-2010-5297 WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. | CVSS2: 2.1 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5297 WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. | CVSS2: 2.1 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5297 WordPress before 3.0.1, when a Multisite installation is used, permane ... | CVSS2: 2.1 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5296 wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. | CVSS2: 4.9 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5296 wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. | CVSS2: 4.9 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5296 wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ... | CVSS2: 4.9 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5295 Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action. | CVSS2: 4.3 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5295 Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action. | CVSS2: 4.3 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5295 Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ... | CVSS2: 4.3 | 2% Низкий | больше 12 лет назад | |
CVE-2010-5294 Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt. | CVSS2: 4.3 | 1% Низкий | больше 12 лет назад | |
CVE-2010-5294 Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt. | CVSS2: 4.3 | 1% Низкий | больше 12 лет назад | |
CVE-2010-5294 Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ... | CVSS2: 4.3 | 1% Низкий | больше 12 лет назад |
Уязвимостей на страницу