Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fcchat Widget MEDIUM 6.8
CVE-2012-3578EPSS 8%

Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to e…

Fix: after 2.2.13.1
Fix from $1,600 2012-06-17
WordPress MEDIUM 6.8
CVE-2012-1936

The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user ses…

Fix: after 3.3.1
Fix from $1,600 2012-05-03
WordPress HIGH 10.0
CVE-2012-2399EPSS 9%

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager …

Fix: after 3.3.1
Fix from $1,950 2012-04-21
WordPress HIGH 10.0
CVE-2012-2400

Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.

Fix: after 3.3.1
Fix from $1,950 2012-04-21
WordPress MEDIUM 5.5
CVE-2012-2402

wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate …

Fix: after 3.3.1
Fix from $1,600 2012-04-21
WordPress MEDIUM 5.0
CVE-2012-2401

Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain f…

Fix: after 3.3.1
Fix from $1,600 2012-04-21
WordPress MEDIUM 5.0
CVE-2012-0937EPSS 8%

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external My…

Fix: after 3.3.1
Fix from $1,600 2012-01-30
WordPress HIGH 7.5
CVE-2011-4899EPSS 9%

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is a…

Fix: after 3.3.1
Fix from $1,950 2012-01-30
WordPress MEDIUM 5.0
CVE-2011-4898EPSS 10%

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbna…

Fix: after 3.3.1
Fix from $1,600 2012-01-30
Wordpress Users HIGH 7.5
CVE-2011-4669

SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remote attackers to execute arbit…

Fix: after 1.3
Fix from $1,950 2011-12-02
WordPress MEDIUM 5.0
CVE-2011-3818

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation…

Mitigation only
Fix from $1,600 2011-09-24
WordPress HIGH 10.0
CVE-2011-3125

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hard…

Patch available
Fix from $1,950 2011-08-10
WordPress HIGH 9.3
CVE-2011-3129

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unkn…

Patch available
Fix from $1,950 2011-08-10
WordPress HIGH 7.5
CVE-2011-3130

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardeni…

Patch available
Fix from $1,950 2011-08-10
WordPress MEDIUM 5.8
CVE-2011-3127

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML doc…

Patch available
Fix from $1,600 2011-08-10
WordPress MEDIUM 5.0
CVE-2011-3126

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

Patch available
Fix from $1,600 2011-08-10
WordPress MEDIUM 5.0
CVE-2011-3128

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive d…

Patch available
Fix from $1,600 2011-08-10
WordPress HIGH 10.0
CVE-2011-3122

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

Patch available
Fix from $1,950 2011-08-10
WordPress MEDIUM 6.0
CVE-2010-4257

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to e…

Fix: after 3.0.1
Fix from $1,600 2010-12-07
WordPress MEDIUM 6.0
CVE-2009-3890EPSS 8%

Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain confi…

Fix: after 2.8.5
Fix from $1,600 2009-11-17
WordPress HIGH 10.0
CVE-2009-2853

Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-…

Patch available
Fix from $1,950 2009-08-18
WordPress MEDIUM 6.4
CVE-2009-2854

Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a d…

Fix: after 2.8.2
Fix from $1,600 2009-08-18
WordPress HIGH 7.5
CVE-2009-2762EPSS 20%

wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the admini…

Fix: after 2.8.3
Fix from $1,950 2009-08-13
WordPress MEDIUM 5.0
CVE-2009-2335EPSS 85%

WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which all…

Fix: 2.8.1+
Fix from $1,600 2009-07-10
WordPress MEDIUM 5.0
CVE-2009-2336EPSS 5%

The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the u…

Fix: 2.8.1+
Fix from $1,600 2009-07-10
WordPress MEDIUM 5.0
CVE-2009-2431

WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading t…

Patch available
Fix from $1,600 2009-07-10
WordPress MEDIUM 5.0
CVE-2009-2432

WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals…

Fix: after 2.7.1
Fix from $1,600 2009-07-10
WordPress HIGH 10.0
CVE-2008-6767

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (applic…

No fix yet
Fix from $1,950 2009-04-28
WordPress HIGH 8.5
CVE-2008-5695EPSS 12%

wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which al…

Fix: 1.3.2+
Fix from $1,950 2008-12-19
WordPress HIGH 9.3
CVE-2008-4769EPSS 9%

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remo…

Fix: after 2.3.3
Fix from $1,950 2008-10-28