Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-63030 KEVEPSS 96% WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n… WordPress 6.9.5 / 7.0.2+ Fix from $2,3002026-07-17 MEDIUM 5.9 CVE-2026-60137 KEVEPSS 73% WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c… WordPress 6.8.6 / 6.9.5+ Fix from $1,6002026-07-17 MEDIUM 5.4 CVE-2022-4973 WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the… WordPress after 6.0.2 Fix from $1,6002024-10-16 HIGH 7.2 CVE-2024-8914 The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to Stored Cross-Site Scr… Thanh Toan Quet Ma Qr Code Tu Dong after 2.0.1 Fix from $1,9502024-09-25 MEDIUM 6.1 CVE-2024-4439EPSS 71% WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insuffi… WordPress after 6.5.1 Fix from $1,6002024-05-03 CRITICAL 9.8 CVE-2024-31211 WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__… WordPress 6.4.2+ Fix from $2,3002024-04-04 HIGH 8.8 CVE-2024-31210 WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an … WordPress 4.1.40 / 4.2.37+ Fix from $1,9502024-04-04 MEDIUM 5.3 CVE-2023-5561 WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addre… WordPress 4.7.27 / 4.8.23+ Fix from $1,6002023-10-16 MEDIUM 5.4 CVE-2023-38000 Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.… WordPress after 16.8.0 Fix from $1,6002023-10-13 HIGH 8.8 CVE-2013-10027 A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/re… Blogger Importer 0.6+ Fix from $1,9502023-06-04 HIGH 8.8 CVE-2022-47174 Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions. Performance Lab after 2.2.0 Fix from $1,9502023-05-25 HIGH 8.8 CVE-2022-47161 Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions. Health Check \& Troubleshooting after 1.5.1 Fix from $1,9502023-05-25 MEDIUM 5.4 CVE-2023-2745EPSS 80% WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated a… WordPress 4.1.38 / 4.2.35+ Fix from $1,6002023-05-17 MEDIUM 6.1 CVE-2013-10021 A vulnerability was found in dd32 Debug Bar Plugin up to 0.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is the… Debug Bar 0.8.1+ Fix from $1,6002023-03-11 MEDIUM 5.3 CVE-2023-22622 WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code… WordPress after 6.1.1 Fix from $1,6002023-01-05 MEDIUM 5.9 CVE-2022-3590 WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and … WordPress after 6.1.1 Fix from $1,6002022-12-14 MEDIUM 6.1 CVE-2022-43497 Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The d… WordPress 3.7.40 / 3.8.40+ Fix from $1,6002022-12-05 MEDIUM 6.1 CVE-2022-43500 Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The d… WordPress 3.7.40 / 3.8.40+ Fix from $1,6002022-12-05 MEDIUM 5.3 CVE-2022-43504 Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of th… WordPress 3.7.40 / 3.8.40+ Fix from $1,6002022-12-05 MEDIUM 6.5 CVE-2011-1762 A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow… WordPress 3.0.6 / 3.1.2+ Fix from $1,6002022-04-18 HIGH 8.8 CVE-2022-21664 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization i… WordPress 5.8.3+ Fix from $1,9502022-01-06 HIGH 7.2 CVE-2022-21663 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm… WordPress 5.8.3+ Fix from $1,9502022-01-06 MEDIUM 5.4 CVE-2022-21662EPSS 65% WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (… WordPress 5.8.3+ Fix from $1,6002022-01-06 HIGH 7.5 CVE-2022-21661EPSS 98% WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Q… WordPress 3.7.37 / 3.8.37+ Fix from $1,9502022-01-06 CRITICAL 9.8 CVE-2021-44223EPSS 29% WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply… WordPress 5.8+ Fix from $2,3002021-11-25 MEDIUM 6.5 CVE-2021-39203 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen… WordPress Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.4 CVE-2021-39201 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows… WordPress 5.8+ Fix from $1,6002021-09-09 MEDIUM 5.4 CVE-2021-39202 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the wi… WordPress Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.3 CVE-2021-39200 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output… WordPress 5.8.1+ Fix from $1,6002021-09-09 CRITICAL 9.8 CVE-2020-36326 PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV… WordPress 3.7.36 / 3.8.36+ Fix from $2,3002021-04-28