Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

WordPress MEDIUM 5.0
CVE-2006-3389

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, whi…

Mitigation only
Fix from $1,600 2006-07-06
WordPress MEDIUM 5.0
CVE-2006-3390

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2)…

Mitigation only
Fix from $1,600 2006-07-06
WordPress MEDIUM 5.0
CVE-2006-2702

vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, w…

No fix yet
Fix from $1,600 2006-05-31
WordPress HIGH 7.5
CVE-2006-2667EPSS 15%

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carria…

Fix: after 2.0.2
Fix from $1,950 2006-05-30
WordPress MEDIUM 6.8
CVE-2006-1796

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other ver…

Fix: after 2.0
Fix from $1,600 2006-04-17
WordPress HIGH 7.5
CVE-2006-1012

SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via…

Patch available
Fix from $1,950 2006-03-06
WordPress MEDIUM 5.0
CVE-2006-0986

WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loa…

Patch available
Fix from $1,600 2006-03-03
WordPress MEDIUM 5.0
CVE-2005-4463

WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugi…

No fix yet
Fix from $1,600 2005-12-21
WordPress HIGH 7.5
CVE-2005-2612EPSS 39%

Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate…

No fix yet
Fix from $1,950 2005-08-17
WordPress HIGH 7.5
CVE-2005-2108EPSS 9%

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input tha…

Patch available
Fix from $1,950 2005-07-05
WordPress MEDIUM 5.0
CVE-2005-2109

wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message …

Patch available
Fix from $1,600 2005-07-05
WordPress MEDIUM 5.0
CVE-2005-2110

WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in t…

Patch available
Fix from $1,600 2005-07-05
WordPress HIGH 7.5
CVE-2005-1810

SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $…

Patch available
Fix from $1,950 2005-06-01
WordPress HIGH 7.5
CVE-2005-1687

SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id …

Mitigation only
Fix from $1,950 2005-05-20
WordPress MEDIUM 5.3
CVE-2005-1688

Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-inc…

Fix: after 1.5
Fix from $1,600 2005-05-20
WordPress MEDIUM 6.8
CVE-2005-1102

Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arb…

Fix: after 1.5
Fix from $1,600 2005-05-02
WordPress MEDIUM 5.0
CVE-2004-1584EPSS 11%

CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected H…

Patch available
Fix from $1,600 2004-12-31