Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

WordPress MEDIUM 6.1
CVE-2019-16222

WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting …

Fix: 5.2.3+
Fix from $1,600 2019-09-11
WordPress MEDIUM 5.4
CVE-2019-16223EPSS 5%

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

Fix: 5.2.3+
Fix from $1,600 2019-09-11
WordPress MEDIUM 6.1
CVE-2019-16217

WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.

Fix: 5.2.3+
Fix from $1,600 2019-09-11
WordPress MEDIUM 6.1
CVE-2019-16218

WordPress before 5.2.3 allows XSS in stored comments.

Fix: 5.2.3+
Fix from $1,600 2019-09-11
WordPress MEDIUM 6.1
CVE-2019-16219

WordPress before 5.2.3 allows XSS in shortcode previews.

Fix: 5.2.3+
Fix from $1,600 2019-09-11
WordPress MEDIUM 6.1
CVE-2019-16220

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect i…

Fix: 5.2.3+
Fix from $1,600 2019-09-11
WordPress MEDIUM 5.3
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/o…

Mitigation only
Fix from $1,600 2019-05-22
WordPress HIGH 8.8
CVE-2019-9787EPSS 41%

WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration…

Fix: 5.1.1+
Fix from $1,950 2019-03-14
WordPress HIGH 8.8
CVE-2019-8942EPSS 83%

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary …

Fix: 4.9.9+
Fix from $1,950 2019-02-20
WordPress MEDIUM 6.5
CVE-2019-8943EPSS 93%

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an …

Fix: after 5.0.3
Fix from $1,600 2019-02-20
WordPress CRITICAL 9.8
CVE-2018-20148EPSS 27%

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XML…

Fix: 4.9.9 / 5.0.1+
Fix from $2,300 2018-12-14
WordPress HIGH 7.5
CVE-2018-20151EPSS 6%

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration w…

Fix: 4.9.9 / 5.0.1+
Fix from $1,950 2018-12-14
WordPress MEDIUM 6.5
CVE-2018-20147

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.

Fix: 4.9.9 / 5.0.1+
Fix from $1,600 2018-12-14
WordPress MEDIUM 6.5
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

Fix: 4.9.9 / 5.0.1+
Fix from $1,600 2018-12-14
WordPress MEDIUM 6.1
CVE-2018-20150

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

Fix: 4.9.9 / 5.0.1+
Fix from $1,600 2018-12-14
WordPress MEDIUM 5.4
CVE-2018-20149

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME typ…

Fix: 4.9.9 / 5.0.1+
Fix from $1,600 2018-12-14
WordPress MEDIUM 5.4
CVE-2018-20153

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

Fix: 4.9.9 / 5.0.1+
Fix from $1,600 2018-12-14
WordPress HIGH 8.8
CVE-2018-1000773EPSS 8%

WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution…

Fix: after 4.9.8
Fix from $1,950 2018-09-06
WordPress HIGH 8.8
CVE-2017-1000600

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack…

Fix: 4.9+
Fix from $1,950 2018-09-06
WordPress HIGH 7.2
CVE-2018-14028EPSS 15%

In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP fil…

Patch available
Fix from $1,950 2018-08-10
WordPress HIGH 8.8
CVE-2018-12895EPSS 63%

WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, whi…

Fix: 4.9.7+
Fix from $1,950 2018-06-26
WordPress MEDIUM 6.1
CVE-2018-10100

Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

Fix: 4.9.5+
Fix from $1,600 2018-04-16
WordPress MEDIUM 6.1
CVE-2018-10101

Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

Fix: 4.9.5+
Fix from $1,600 2018-04-16
WordPress MEDIUM 6.1
CVE-2018-10102

Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.

Fix: 4.9.5+
Fix from $1,600 2018-04-16
WordPress HIGH 8.1
CVE-2014-6412

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

Fix: 4.4.0+
Fix from $1,950 2018-04-12
WordPress HIGH 7.5
CVE-2018-6389EPSS 73%

In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js …

Fix: after 4.9.2
Fix from $1,950 2018-02-06
WordPress MEDIUM 6.1
CVE-2018-5776

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

Fix: 4.9.2+
Fix from $1,600 2018-01-18
WordPress HIGH 8.8
CVE-2017-17091EPSS 7%

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remo…

Fix: after 4.9
Fix from $1,950 2017-12-02
WordPress MEDIUM 5.4
CVE-2017-17092

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote…

Fix: 4.9.1+
Fix from $1,600 2017-12-02
WordPress MEDIUM 5.4
CVE-2017-17093

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attack…

Fix: 4.9.1+
Fix from $1,600 2017-12-02