Vulnerability index

Browse CVEs

45 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

WordPress MEDIUM 6.5
CVE-2021-39203

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen…

Mitigation only
Fix from $1,600 2021-09-09
WordPress MEDIUM 5.4
CVE-2021-39202

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the wi…

Mitigation only
Fix from $1,600 2021-09-09
WordPress MEDIUM 5.3
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/o…

Mitigation only
Fix from $1,600 2019-05-22
WordPress MEDIUM 6.5
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which mig…

No fix yet
Fix from $1,600 2017-10-03
WordPress HIGH 7.1
CVE-2016-6896EPSS 38%

Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authen…

No fix yet
Fix from $1,950 2017-01-18
WordPress HIGH 7.5
CVE-2003-1599

PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,950 2014-10-27
WordPress MEDIUM 5.0
CVE-2013-7240EPSS 20%

Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary f…

No fix yet
Fix from $1,600 2014-01-03
WordPress MEDIUM 6.8
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of admi…

No fix yet
Fix from $1,600 2012-09-28
Plugin Newsletter Plugin MEDIUM 5.0
CVE-2012-3588EPSS 11%

Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files vi…

No fix yet
Fix from $1,600 2012-06-19
WordPress MEDIUM 5.0
CVE-2011-3818

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation…

Mitigation only
Fix from $1,600 2011-09-24
WordPress HIGH 10.0
CVE-2008-6767

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (applic…

No fix yet
Fix from $1,950 2009-04-28
Spambam Plugin MEDIUM 5.0
CVE-2008-4616EPSS 7%

The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a …

Mitigation only
Fix from $1,600 2008-10-20
Wp Downloads Manager HIGH 10.0
CVE-2008-3362EPSS 17%

Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exe…

No fix yet
Fix from $1,950 2008-07-30
Upload File Plugin HIGH 7.5
CVE-2008-2510

SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands vi…

Mitigation only
Fix from $1,950 2008-05-29
Download Monitor Plugin HIGH 7.5
CVE-2008-2034

SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute…

Mitigation only
Fix from $1,950 2008-04-30
Wp Download HIGH 7.5
CVE-2008-1646

SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands …

No fix yet
Fix from $1,950 2008-04-02
Sniplets Plugin HIGH 7.5
CVE-2008-1059EPSS 48%

PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers …

No fix yet
Fix from $1,950 2008-02-28
Sniplets Plugin HIGH 7.5
CVE-2008-1060EPSS 44%

Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,950 2008-02-28
Photo Album Plugin HIGH 7.5
CVE-2008-0939

Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arb…

No fix yet
Fix from $1,950 2008-02-25
Dean Logan Wp People Plugin HIGH 7.5
CVE-2008-0845

SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2008-02-20
St Newsletter Plugin HIGH 7.5
CVE-2008-0683

SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to exec…

No fix yet
Fix from $1,950 2008-02-12
Adserve HIGH 7.5
CVE-2008-0507

SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,950 2008-01-31
Wp Cal Plugin HIGH 7.5
CVE-2008-0490

SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL comman…

No fix yet
Fix from $1,950 2008-01-30
Wp Forum MEDIUM 6.8
CVE-2008-0388

SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramet…

No fix yet
Fix from $1,600 2008-01-23
Filemanager HIGH 7.5
CVE-2008-0222EPSS 8%

Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and ex…

No fix yet
Fix from $1,950 2008-01-10
WordPress MEDIUM 5.0
CVE-2008-0191

WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh…

Mitigation only
Fix from $1,600 2008-01-10
WordPress MEDIUM 6.8
CVE-2007-6318EPSS 9%

SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,600 2007-12-12
Unamed Theme MEDIUM 5.0
CVE-2007-4166

Cross-site scripting (XSS) vulnerability in index.php in the Unnamed theme 1.217, and Special Edition (SE) 1.02, before 20070804 for WordPress allows…

Mitigation only
Fix from $1,600 2007-08-07
WordPress MEDIUM 6.5
CVE-2007-4154

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the pa…

Mitigation only
Fix from $1,600 2007-08-03
WordPress MEDIUM 6.0
CVE-2007-3238

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject …

Mitigation only
Fix from $1,600 2007-06-15