Vulnerability index

Browse CVEs

45 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2021-39203 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen… WordPress Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.4 CVE-2021-39202 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the wi… WordPress Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.3 CVE-2017-6514 WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/o… WordPress Mitigation only Fix from $1,6002019-05-22 MEDIUM 6.5 CVE-2017-14990 WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which mig… WordPress No fix yet Fix from $1,6002017-10-03 HIGH 7.1 CVE-2016-6896EPSS 38% Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authen… WordPress No fix yet Fix from $1,9502017-01-18 HIGH 7.5 CVE-2003-1599 PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL i… WordPress No fix yet Fix from $1,9502014-10-27 MEDIUM 5.0 CVE-2013-7240EPSS 20% Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary f… WordPress No fix yet Fix from $1,6002014-01-03 MEDIUM 6.8 CVE-2012-4448 Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of admi… WordPress No fix yet Fix from $1,6002012-09-28 MEDIUM 5.0 CVE-2012-3588EPSS 11% Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files vi… Plugin Newsletter Plugin No fix yet Fix from $1,6002012-06-19 MEDIUM 5.0 CVE-2011-3818 WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation… WordPress Mitigation only Fix from $1,6002011-09-24 HIGH 10.0 CVE-2008-6767 wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (applic… WordPress No fix yet Fix from $1,9502009-04-28 MEDIUM 5.0 CVE-2008-4616EPSS 7% The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a … Spambam Plugin Mitigation only Fix from $1,6002008-10-20 HIGH 10.0 CVE-2008-3362EPSS 17% Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exe… Wp Downloads Manager No fix yet Fix from $1,9502008-07-30 HIGH 7.5 CVE-2008-2510 SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands vi… Upload File Plugin Mitigation only Fix from $1,9502008-05-29 HIGH 7.5 CVE-2008-2034 SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute… Download Monitor Plugin Mitigation only Fix from $1,9502008-04-30 HIGH 7.5 CVE-2008-1646 SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands … Wp Download No fix yet Fix from $1,9502008-04-02 HIGH 7.5 CVE-2008-1059EPSS 48% PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers … Sniplets Plugin No fix yet Fix from $1,9502008-02-28 HIGH 7.5 CVE-2008-1060EPSS 44% Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary… Sniplets Plugin No fix yet Fix from $1,9502008-02-28 HIGH 7.5 CVE-2008-0939 Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arb… Photo Album Plugin No fix yet Fix from $1,9502008-02-25 HIGH 7.5 CVE-2008-0845 SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQ… Dean Logan Wp People Plugin Mitigation only Fix from $1,9502008-02-20 HIGH 7.5 CVE-2008-0683 SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to exec… St Newsletter Plugin No fix yet Fix from $1,9502008-02-12 HIGH 7.5 CVE-2008-0507 SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the … Adserve No fix yet Fix from $1,9502008-01-31 HIGH 7.5 CVE-2008-0490 SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL comman… Wp Cal Plugin No fix yet Fix from $1,9502008-01-30 MEDIUM 6.8 CVE-2008-0388 SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramet… Wp Forum No fix yet Fix from $1,6002008-01-23 HIGH 7.5 CVE-2008-0222EPSS 8% Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and ex… Filemanager No fix yet Fix from $1,9502008-01-10 MEDIUM 5.0 CVE-2008-0191 WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh… WordPress Mitigation only Fix from $1,6002008-01-10 MEDIUM 6.8 CVE-2007-6318EPSS 9% SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the… WordPress No fix yet Fix from $1,6002007-12-12 MEDIUM 5.0 CVE-2007-4166 Cross-site scripting (XSS) vulnerability in index.php in the Unnamed theme 1.217, and Special Edition (SE) 1.02, before 20070804 for WordPress allows… Unamed Theme Mitigation only Fix from $1,6002007-08-07 MEDIUM 6.5 CVE-2007-4154 SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the pa… WordPress Mitigation only Fix from $1,6002007-08-03 MEDIUM 6.0 CVE-2007-3238 Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject … WordPress Mitigation only Fix from $1,6002007-06-15