Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2021-39203
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen…
WordPress
Mitigation only
MEDIUM 5.4
CVE-2021-39202
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the wi…
WordPress
Mitigation only
MEDIUM 5.3
CVE-2017-6514
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/o…
WordPress
Mitigation only
MEDIUM 6.5
CVE-2017-14990
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which mig…
WordPress
No fix yet
HIGH 7.1
CVE-2016-6896EPSS 38%
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authen…
WordPress
No fix yet
HIGH 7.5
CVE-2003-1599
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL i…
WordPress
No fix yet
MEDIUM 5.0
CVE-2013-7240EPSS 20%
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary f…
WordPress
No fix yet
MEDIUM 6.8
CVE-2012-4448
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of admi…
WordPress
No fix yet
MEDIUM 5.0
CVE-2012-3588EPSS 11%
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files vi…
Plugin Newsletter Plugin
No fix yet
MEDIUM 5.0
CVE-2011-3818
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation…
WordPress
Mitigation only
HIGH 10.0
CVE-2008-6767
wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (applic…
WordPress
No fix yet
MEDIUM 5.0
CVE-2008-4616EPSS 7%
The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a …
Spambam Plugin
Mitigation only
HIGH 10.0
CVE-2008-3362EPSS 17%
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exe…
Wp Downloads Manager
No fix yet
HIGH 7.5
CVE-2008-2510
SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands vi…
Upload File Plugin
Mitigation only
HIGH 7.5
CVE-2008-2034
SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute…
Download Monitor Plugin
Mitigation only
HIGH 7.5
CVE-2008-1646
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands …
Wp Download
No fix yet
HIGH 7.5
CVE-2008-1059EPSS 48%
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers …
Sniplets Plugin
No fix yet
HIGH 7.5
CVE-2008-1060EPSS 44%
Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary…
Sniplets Plugin
No fix yet
HIGH 7.5
CVE-2008-0939
Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arb…
Photo Album Plugin
No fix yet
HIGH 7.5
CVE-2008-0845
SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQ…
Dean Logan Wp People Plugin
Mitigation only
HIGH 7.5
CVE-2008-0683
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to exec…
St Newsletter Plugin
No fix yet
HIGH 7.5
CVE-2008-0507
SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the …
Adserve
No fix yet
HIGH 7.5
CVE-2008-0490
SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL comman…
Wp Cal Plugin
No fix yet
MEDIUM 6.8
CVE-2008-0388
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramet…
Wp Forum
No fix yet
HIGH 7.5
CVE-2008-0222EPSS 8%
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and ex…
Filemanager
No fix yet
MEDIUM 5.0
CVE-2008-0191
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh…
WordPress
Mitigation only
MEDIUM 6.8
CVE-2007-6318EPSS 9%
SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the…
WordPress
No fix yet
MEDIUM 5.0
CVE-2007-4166
Cross-site scripting (XSS) vulnerability in index.php in the Unnamed theme 1.217, and Special Edition (SE) 1.02, before 20070804 for WordPress allows…
Unamed Theme
Mitigation only
MEDIUM 6.5
CVE-2007-4154
SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the pa…
WordPress
Mitigation only
MEDIUM 6.0
CVE-2007-3238
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject …
WordPress
Mitigation only