Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spambam Plugin MEDIUM 5.0
CVE-2008-4616EPSS 7%

The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a …

Mitigation only
Fix from $1,600 2008-10-20
WordPress MEDIUM 5.1
CVE-2008-4106EPSS 5%

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_l…

Fix: after 2.6.1
Fix from $1,600 2008-09-18
WordPress HIGH 7.5
CVE-2008-3747

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL commun…

Patch available
Fix from $1,950 2008-08-27
Wp Downloads Manager HIGH 10.0
CVE-2008-3362EPSS 17%

Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exe…

No fix yet
Fix from $1,950 2008-07-30
Upload File Plugin HIGH 7.5
CVE-2008-2510

SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands vi…

Mitigation only
Fix from $1,950 2008-05-29
WordPress HIGH 9.0
CVE-2008-2392

Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary…

Fix: after 2.5.1
Fix from $1,950 2008-05-21
WordPress HIGH 7.5
CVE-2008-2146

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attacke…

Fix: after 2.2.2
Fix from $1,950 2008-05-12
Download Monitor Plugin HIGH 7.5
CVE-2008-2034

SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute…

Mitigation only
Fix from $1,950 2008-04-30
WordPress HIGH 7.5
CVE-2008-1930EPSS 5%

The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote …

Patch available
Fix from $1,950 2008-04-28
Wpss HIGH 7.5
CVE-2008-1982

SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrar…

Fix: after 0.6
Fix from $1,950 2008-04-27
Wp Download HIGH 7.5
CVE-2008-1646

SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands …

No fix yet
Fix from $1,950 2008-04-02
Sniplets Plugin HIGH 7.5
CVE-2008-1059EPSS 48%

PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers …

No fix yet
Fix from $1,950 2008-02-28
Sniplets Plugin HIGH 7.5
CVE-2008-1060EPSS 44%

Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,950 2008-02-28
Photo Album Plugin HIGH 7.5
CVE-2008-0939

Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arb…

No fix yet
Fix from $1,950 2008-02-25
Dean Logan Wp People Plugin HIGH 7.5
CVE-2008-0845

SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2008-02-20
Wordspew HIGH 7.5
CVE-2008-0682

SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL com…

Fix: after 3.71
Fix from $1,950 2008-02-12
St Newsletter Plugin HIGH 7.5
CVE-2008-0683

SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to exec…

No fix yet
Fix from $1,950 2008-02-12
WordPress MEDIUM 6.4
CVE-2008-0664

The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog …

Patch available
Fix from $1,600 2008-02-08
Adserve HIGH 7.5
CVE-2008-0507

SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,950 2008-01-31
Wassup Plugin HIGH 7.5
CVE-2008-0520

Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary S…

Fix: after 1.4.3
Fix from $1,950 2008-01-31
Permalinks Migration Plugin MEDIUM 6.8
CVE-2008-0508

Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows …

Patch available
Fix from $1,600 2008-01-31
Wp Cal Plugin HIGH 7.5
CVE-2008-0490

SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL comman…

No fix yet
Fix from $1,950 2008-01-30
Wp Forum MEDIUM 6.8
CVE-2008-0388

SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramet…

No fix yet
Fix from $1,600 2008-01-23
Filemanager HIGH 7.5
CVE-2008-0222EPSS 8%

Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and ex…

No fix yet
Fix from $1,950 2008-01-10
WordPress HIGH 7.5
CVE-2008-0194

Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrar…

Fix: after 2.0.3
Fix from $1,950 2008-01-10
WordPress MEDIUM 5.0
CVE-2008-0191

WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh…

Mitigation only
Fix from $1,600 2008-01-10
WordPress MEDIUM 5.0
CVE-2008-0195

WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts …

Fix: after 2.0.11
Fix from $1,600 2008-01-10
WordPress MEDIUM 5.0
CVE-2008-0196

Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1)…

Fix: after 2.0.11
Fix from $1,600 2008-01-10
Pictpress MEDIUM 5.0
CVE-2007-6369EPSS 8%

Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbi…

Fix: after 0.91
Fix from $1,600 2007-12-15
WordPress MEDIUM 6.8
CVE-2007-6318EPSS 9%

SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,600 2007-12-12