Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

WordPress MEDIUM 5.4
CVE-2017-17094

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct X…

Fix: 4.9.1+
Fix from $1,600 2017-12-02
WordPress CRITICAL 9.8
CVE-2017-16510EPSS 7%

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQ…

Fix: after 4.8.2
Fix from $2,300 2017-11-02
WordPress HIGH 7.5
CVE-2012-6707

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by levera…

Fix: after 4.8.2
Fix from $1,950 2017-10-19
WordPress MEDIUM 6.5
CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which mig…

No fix yet
Fix from $1,600 2017-10-03
WordPress CRITICAL 9.8
CVE-2017-14723EPSS 7%

Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the po…

Fix: after 4.8.1
Fix from $2,300 2017-09-23
WordPress HIGH 7.5
CVE-2017-14719EPSS 14%

Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

Patch available
Fix from $1,950 2017-09-23
WordPress HIGH 7.5
CVE-2017-14722EPSS 8%

Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.

Patch available
Fix from $1,950 2017-09-23
WordPress MEDIUM 6.1
CVE-2017-14718

Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.

Fix: after 4.8.1
Fix from $1,600 2017-09-23
WordPress MEDIUM 6.1
CVE-2017-14720

Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

Fix: after 4.8.1
Fix from $1,600 2017-09-23
WordPress MEDIUM 6.1
CVE-2017-14721

Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.

Fix: after 4.8.1
Fix from $1,600 2017-09-23
WordPress MEDIUM 6.1
CVE-2017-14724

Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

Fix: after 4.8.1
Fix from $1,600 2017-09-23
WordPress MEDIUM 6.1
CVE-2017-14726

Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

Fix: after 4.8.1
Fix from $1,600 2017-09-23
WordPress MEDIUM 5.4
CVE-2017-14725

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

Fix: after 4.8.1
Fix from $1,600 2017-09-23
WordPress HIGH 8.8
CVE-2017-9064

In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not requi…

Fix: after 4.7.4
Fix from $1,950 2017-05-18
WordPress HIGH 8.6
CVE-2017-9062

In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

Fix: after 4.7.4
Fix from $1,950 2017-05-18
WordPress HIGH 8.6
CVE-2017-9066

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

Fix: after 4.7.4
Fix from $1,950 2017-05-18
WordPress HIGH 7.5
CVE-2017-9065

In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.

Fix: after 4.7.4
Fix from $1,950 2017-05-18
WordPress MEDIUM 6.1
CVE-2017-9061

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message do…

Fix: after 4.7.4
Fix from $1,600 2017-05-18
WordPress MEDIUM 6.1
CVE-2017-9063

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.

Fix: after 4.7.4
Fix from $1,600 2017-05-18
WordPress MEDIUM 5.9
CVE-2017-8295EPSS 27%

WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbit…

Fix: after 4.7.4
Fix from $1,600 2017-05-04
WordPress HIGH 7.5
CVE-2017-1001000EPSS 85%

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 doe…

Patch available
Fix from $1,950 2017-04-03
WordPress MEDIUM 6.5
CVE-2017-6819

In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive…

Fix: after 4.7.2
Fix from $1,600 2017-03-12
WordPress MEDIUM 6.1
CVE-2017-6815

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

Fix: after 4.7.2
Fix from $1,600 2017-03-12
WordPress MEDIUM 6.1
CVE-2017-6818

In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.

Fix: after 4.7.2
Fix from $1,600 2017-03-12
WordPress MEDIUM 5.4
CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of…

Fix: after 4.7.2
Fix from $1,600 2017-03-12
WordPress MEDIUM 5.4
CVE-2017-6817

In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.

Fix: after 4.7.2
Fix from $1,600 2017-03-12
WordPress CRITICAL 9.8
CVE-2017-5611EPSS 10%

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL …

Fix: after 4.7.1
Fix from $2,300 2017-01-30
WordPress MEDIUM 6.1
CVE-2017-5612

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows …

Fix: after 4.7.1
Fix from $1,600 2017-01-30
WordPress MEDIUM 5.3
CVE-2017-5610EPSS 5%

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user…

Fix: after 4.7.1
Fix from $1,600 2017-01-30
WordPress HIGH 7.1
CVE-2016-6896EPSS 38%

Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authen…

No fix yet
Fix from $1,950 2017-01-18