Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

WordPress MEDIUM 6.5
CVE-2016-6897EPSS 28%

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 a…

Fix: after 4.5.5
Fix from $1,600 2017-01-18
WordPress HIGH 8.8
CVE-2017-5492

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to…

Fix: after 4.7
Fix from $1,950 2017-01-15
WordPress HIGH 7.5
CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes i…

Fix: after 4.7
Fix from $1,950 2017-01-15
WordPress HIGH 8.8
CVE-2017-5489

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims…

Fix: after 4.7
Fix from $1,950 2017-01-15
WordPress MEDIUM 6.1
CVE-2017-5488

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary …

Fix: after 4.7
Fix from $1,600 2017-01-15
WordPress MEDIUM 6.1
CVE-2017-5490

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows …

Fix: after 4.7
Fix from $1,600 2017-01-15
WordPress MEDIUM 5.3
CVE-2017-5487EPSS 87%

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly rest…

Fix: after 4.7
Fix from $1,600 2017-01-15
WordPress MEDIUM 5.3
CVE-2017-5491

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.ex…

Fix: after 4.7
Fix from $1,600 2017-01-15
WordPress MEDIUM 6.3
CVE-2016-7169

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package upload…

Fix: after 4.6
Fix from $1,600 2017-01-05
WordPress CRITICAL 9.8
CVE-2016-10033 KEVEPSS 100%

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command an…

Fix: 5.2.18+
Fix from $2,300 2016-12-30
WordPress CRITICAL 9.8
CVE-2016-10045EPSS 98%

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute ar…

Fix: 5.2.20+
Fix from $2,300 2016-12-30
WordPress HIGH 8.8
CVE-2016-6635

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before…

Fix: after 4.4.2
Fix from $1,950 2016-08-07
WordPress MEDIUM 6.1
CVE-2016-6634

Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script …

Fix: after 4.4.4
Fix from $1,600 2016-08-07
WordPress HIGH 8.6
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers t…

Fix: 4.5+
Fix from $1,950 2016-08-07
WordPress HIGH 7.5
CVE-2016-5839

WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.

Fix: after 4.5.2
Fix from $1,950 2016-06-29
WordPress HIGH 7.5
CVE-2016-5838

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

Fix: after 4.5.2
Fix from $1,950 2016-06-29
WordPress HIGH 7.5
CVE-2016-5837

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vec…

Fix: after 4.5.2
Fix from $1,950 2016-06-29
WordPress HIGH 7.5
CVE-2016-5836

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

Fix: after 4.5.2
Fix from $1,950 2016-06-29
WordPress HIGH 7.5
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to …

Fix: after 4.5.2
Fix from $1,950 2016-06-29
WordPress MEDIUM 6.1
CVE-2016-5834

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows rem…

Fix: after 4.5.2
Fix from $1,600 2016-06-29
WordPress MEDIUM 6.1
CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 al…

Fix: after 4.5.2
Fix from $1,600 2016-06-29
WordPress HIGH 7.5
CVE-2016-5832

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

Fix: after 4.5.2
Fix from $1,950 2016-06-29
WordPress MEDIUM 6.1
CVE-2016-4567EPSS 7%

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows re…

Fix: after 4.5.1
Fix from $1,600 2016-05-22
WordPress MEDIUM 6.1
CVE-2016-4566EPSS 6%

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers t…

Fix: after 4.5.1
Fix from $1,600 2016-05-22
WordPress HIGH 8.6
CVE-2016-2222EPSS 8%

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (S…

Patch available
Fix from $1,950 2016-05-22
WordPress HIGH 7.4
CVE-2016-2221

Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to re…

Fix: after 4.4.1
Fix from $1,950 2016-05-22
WordPress MEDIUM 6.1
CVE-2016-1564

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbi…

Fix: after 4.4.0
Fix from $1,600 2016-05-22
WordPress MEDIUM 6.1
CVE-2015-8834

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or…

Fix: after 4.2.1
Fix from $1,600 2016-05-22
WordPress MEDIUM 5.4
CVE-2015-7989

Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web s…

Fix: after 4.3.0
Fix from $1,600 2016-05-22
WordPress MEDIUM 6.1
CVE-2015-5714EPSS 7%

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the m…

Fix: after 4.3.0
Fix from $1,600 2016-05-22