Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

WordPress CRITICAL 9.8
CVE-2007-6013

Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtai…

Fix: after 2.3.1
Fix from $2,300 2007-11-19
WordPress HIGH 7.5
CVE-2007-4894

Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitr…

Patch available
Fix from $1,950 2007-09-14
Unamed Theme MEDIUM 5.0
CVE-2007-4166

Cross-site scripting (XSS) vulnerability in index.php in the Unnamed theme 1.217, and Special Edition (SE) 1.02, before 20070804 for WordPress allows…

Mitigation only
Fix from $1,600 2007-08-07
WordPress MEDIUM 6.5
CVE-2007-4154

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the pa…

Mitigation only
Fix from $1,600 2007-08-03
WordPress MEDIUM 6.5
CVE-2007-3544

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users …

Fix: after 2.2.0
Fix from $1,600 2007-07-03
WordPress MEDIUM 6.0
CVE-2007-3543

Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execut…

Fix: after 2.2.0
Fix from $1,600 2007-07-03
WordPress MEDIUM 6.0
CVE-2007-3238

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject …

Mitigation only
Fix from $1,600 2007-06-15
WordPress MEDIUM 6.5
CVE-2007-3140EPSS 7%

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value …

No fix yet
Fix from $1,600 2007-06-08
WordPress HIGH 7.5
CVE-2007-2821EPSS 5%

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cook…

Fix: after 2.1.3
Fix from $1,950 2007-05-22
WordPress MEDIUM 6.8
CVE-2007-2627

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers t…

Mitigation only
Fix from $1,600 2007-05-11
WordPress MEDIUM 6.5
CVE-2007-1897EPSS 7%

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary S…

Fix: after 2.1.2
Fix from $1,600 2007-04-09
WordPress MEDIUM 6.5
CVE-2007-1599

wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via …

Mitigation only
Fix from $1,600 2007-03-22
WordPress MEDIUM 5.0
CVE-2007-1409

WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an…

Mitigation only
Fix from $1,600 2007-03-10
WordPress HIGH 7.5
CVE-2007-1277EPSS 27%

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that …

No fix yet
Fix from $1,950 2007-03-05
WordPress MEDIUM 6.8
CVE-2007-1244EPSS 7%

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged action…

Fix: after 2.1.1
Fix from $1,600 2007-03-03
WordPress MEDIUM 5.8
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arb…

Patch available
Fix from $1,600 2007-03-02
WordPress HIGH 7.8
CVE-2007-0539

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingb…

Fix: after 2.0
Fix from $1,950 2007-01-29
WordPress MEDIUM 5.0
CVE-2007-0540EPSS 7%

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that co…

Fix: after 2.0
Fix from $1,600 2007-01-29
WordPress MEDIUM 5.0
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service ca…

Fix: after 2.0
Fix from $1,600 2007-01-29
WordPress HIGH 7.8
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attacke…

Mitigation only
Fix from $1,950 2007-01-16
WordPress HIGH 7.5
CVE-2007-0233EPSS 12%

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value match…

No fix yet
Fix from $1,950 2007-01-13
WordPress MEDIUM 6.8
CVE-2007-0106

Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web scri…

Patch available
Fix from $1,600 2007-01-09
WordPress MEDIUM 6.8
CVE-2007-0107EPSS 8%

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attacker…

Fix: after 2.0.5
Fix from $1,600 2007-01-09
WordPress MEDIUM 5.0
CVE-2007-0109

wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensit…

Mitigation only
Fix from $1,600 2007-01-09
WordPress MEDIUM 6.8
CVE-2006-6808EPSS 7%

Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML …

Fix: after 2.0.5
Fix from $1,600 2006-12-28
WordPress MEDIUM 6.5
CVE-2006-6016

wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id p…

Fix: after 2.0.4
Fix from $1,600 2006-11-21
WordPress MEDIUM 6.5
CVE-2006-6017

WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated…

Fix: after 2.0.5
Fix from $1,600 2006-11-21
WordPress MEDIUM 6.0
CVE-2006-5705

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwr…

Fix: after 2.0.4
Fix from $1,600 2006-11-04
WordPress MEDIUM 5.0
CVE-2006-4743

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) arch…

Mitigation only
Fix from $1,600 2006-09-13
WordPress HIGH 10.0
CVE-2006-4028

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is no…

Patch available
Fix from $1,950 2006-08-09