Vulnerability index

Browse CVEs

45 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

WordPress MEDIUM 6.5
CVE-2007-3140EPSS 7%

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value …

No fix yet
Fix from $1,600 2007-06-08
WordPress MEDIUM 6.8
CVE-2007-2627

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers t…

Mitigation only
Fix from $1,600 2007-05-11
WordPress MEDIUM 6.5
CVE-2007-1599

wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via …

Mitigation only
Fix from $1,600 2007-03-22
WordPress MEDIUM 5.0
CVE-2007-1409

WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an…

Mitigation only
Fix from $1,600 2007-03-10
WordPress HIGH 7.5
CVE-2007-1277EPSS 27%

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that …

No fix yet
Fix from $1,950 2007-03-05
WordPress HIGH 7.8
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attacke…

Mitigation only
Fix from $1,950 2007-01-16
WordPress HIGH 7.5
CVE-2007-0233EPSS 12%

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value match…

No fix yet
Fix from $1,950 2007-01-13
WordPress MEDIUM 5.0
CVE-2007-0109

wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensit…

Mitigation only
Fix from $1,600 2007-01-09
WordPress MEDIUM 5.0
CVE-2006-4743

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) arch…

Mitigation only
Fix from $1,600 2006-09-13
WordPress MEDIUM 5.0
CVE-2006-3389

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, whi…

Mitigation only
Fix from $1,600 2006-07-06
WordPress MEDIUM 5.0
CVE-2006-3390

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2)…

Mitigation only
Fix from $1,600 2006-07-06
WordPress MEDIUM 5.0
CVE-2006-2702

vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, w…

No fix yet
Fix from $1,600 2006-05-31
WordPress MEDIUM 5.0
CVE-2005-4463

WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugi…

No fix yet
Fix from $1,600 2005-12-21
WordPress HIGH 7.5
CVE-2005-2612EPSS 39%

Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate…

No fix yet
Fix from $1,950 2005-08-17
WordPress HIGH 7.5
CVE-2005-1687

SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id …

Mitigation only
Fix from $1,950 2005-05-20