Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

WordPress MEDIUM 6.8
CVE-2015-5731

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication o…

Fix: after 4.2.3
Fix from $1,600 2015-11-09
WordPress MEDIUM 5.0
CVE-2015-5730EPSS 7%

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison…

Fix: after 4.2.3
Fix from $1,600 2015-11-09
WordPress HIGH 7.5
CVE-2015-2213EPSS 9%

SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to exe…

Fix: after 4.2.3
Fix from $1,950 2015-11-09
WordPress MEDIUM 6.4
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct serve…

Fix: after 3.7.4
Fix from $1,600 2014-11-25
WordPress MEDIUM 6.8
CVE-2014-9037

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle…

Fix: after 3.7.4
Fix from $1,600 2014-11-25
WordPress MEDIUM 5.0
CVE-2014-9034EPSS 83%

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause…

Fix: after 3.7.4
Fix from $1,600 2014-11-25
WordPress MEDIUM 6.8
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authe…

Patch available
Fix from $1,600 2014-11-25
WordPress HIGH 7.5
CVE-2003-1599

PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,950 2014-10-27
WordPress HIGH 7.5
CVE-2003-1598

SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts va…

Fix: after 0.7
Fix from $1,950 2014-10-01
WordPress MEDIUM 5.0
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations with…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
WordPress MEDIUM 5.0
CVE-2014-5266EPSS 24%

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of ele…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
WordPress HIGH 7.5
CVE-2014-5203

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbit…

Patch available
Fix from $1,950 2014-08-18
WordPress MEDIUM 6.8
CVE-2014-5205

wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, whic…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
WordPress MEDIUM 6.4
CVE-2014-0166EPSS 9%

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the va…

Fix: after 3.7.1
Fix from $1,600 2014-04-10
WordPress MEDIUM 6.4
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restr…

Fix: after 3.3.2
Fix from $1,600 2014-01-21
WordPress MEDIUM 5.8
CVE-2010-5293

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers…

Fix: after 3.0.1
Fix from $1,600 2014-01-21
WordPress MEDIUM 5.0
CVE-2013-7240EPSS 20%

Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary f…

No fix yet
Fix from $1,600 2014-01-03
WordPress MEDIUM 6.8
CVE-2013-7233

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows …

Fix: after 2.0.11
Fix from $1,600 2013-12-30
WordPress HIGH 7.5
CVE-2013-4339EPSS 7%

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection r…

Fix: after 3.6
Fix from $1,950 2013-09-12
WordPress HIGH 7.5
CVE-2013-4338EPSS 9%

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to ex…

Fix: after 3.6
Fix from $1,950 2013-09-12
WordPress MEDIUM 6.4
CVE-2013-0235EPSS 29%

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by spe…

Fix: after 3.5.0
Fix from $1,600 2013-07-08
Wp Maintenance Mode Plugin MEDIUM 6.8
CVE-2013-3250

Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the au…

Fix: after 1.8.7
Fix from $1,600 2013-06-21
WordPress HIGH 7.5
CVE-2011-5216

SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary S…

Fix: after 1.0.6.6
Fix from $1,950 2012-10-25
Pay With Tweet MEDIUM 6.0
CVE-2012-5350

SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execu…

Fix: after 1.1
Fix from $1,600 2012-10-09
WordPress MEDIUM 6.8
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of admi…

No fix yet
Fix from $1,600 2012-09-28
WordPress MEDIUM 6.5
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticat…

Fix: after 3.0.2
Fix from $1,600 2012-09-14
WordPress MEDIUM 6.8
CVE-2012-3384

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of u…

Fix: after 3.4.0
Fix from $1,600 2012-07-22
WordPress MEDIUM 5.0
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors…

Fix: after 3.4.0
Fix from $1,600 2012-07-22
WordPress MEDIUM 5.0
CVE-2011-4957

The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE libr…

Fix: after 3.1
Fix from $1,600 2012-06-27
Plugin Newsletter Plugin MEDIUM 5.0
CVE-2012-3588EPSS 11%

Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files vi…

No fix yet
Fix from $1,600 2012-06-19