Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2019-16222
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting …
WordPress
5.2.3+
MEDIUM 5.4
CVE-2019-16223EPSS 5%
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
WordPress
5.2.3+
MEDIUM 6.1
CVE-2019-16217
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
WordPress
5.2.3+
MEDIUM 6.1
CVE-2019-16218
WordPress before 5.2.3 allows XSS in stored comments.
WordPress
5.2.3+
MEDIUM 6.1
CVE-2019-16219
WordPress before 5.2.3 allows XSS in shortcode previews.
WordPress
5.2.3+
MEDIUM 6.1
CVE-2019-16220
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect i…
WordPress
5.2.3+
MEDIUM 5.3
CVE-2017-6514
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/o…
WordPress
Mitigation only
HIGH 8.8
CVE-2019-9787EPSS 41%
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration…
WordPress
5.1.1+
HIGH 8.8
CVE-2019-8942EPSS 83%
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary …
WordPress
4.9.9+
MEDIUM 6.5
CVE-2019-8943EPSS 93%
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an …
WordPress
after 5.0.3
CRITICAL 9.8
CVE-2018-20148EPSS 27%
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XML…
WordPress
4.9.9 / 5.0.1+
HIGH 7.5
CVE-2018-20151EPSS 6%
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration w…
WordPress
4.9.9 / 5.0.1+
MEDIUM 6.5
CVE-2018-20147
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.
WordPress
4.9.9 / 5.0.1+
MEDIUM 6.5
CVE-2018-20152
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.
WordPress
4.9.9 / 5.0.1+
MEDIUM 6.1
CVE-2018-20150
In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
WordPress
4.9.9 / 5.0.1+
MEDIUM 5.4
CVE-2018-20149
In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME typ…
WordPress
4.9.9 / 5.0.1+
MEDIUM 5.4
CVE-2018-20153
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
WordPress
4.9.9 / 5.0.1+
HIGH 8.8
CVE-2018-1000773EPSS 8%
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution…
WordPress
after 4.9.8
HIGH 8.8
CVE-2017-1000600
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack…
WordPress
4.9+
HIGH 7.2
CVE-2018-14028EPSS 15%
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP fil…
WordPress
Patch available
HIGH 8.8
CVE-2018-12895EPSS 63%
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, whi…
WordPress
4.9.7+
MEDIUM 6.1
CVE-2018-10100
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
WordPress
4.9.5+
MEDIUM 6.1
CVE-2018-10101
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
WordPress
4.9.5+
MEDIUM 6.1
CVE-2018-10102
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
WordPress
4.9.5+
HIGH 8.1
CVE-2014-6412
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
WordPress
4.4.0+
HIGH 7.5
CVE-2018-6389EPSS 73%
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js …
WordPress
after 4.9.2
MEDIUM 6.1
CVE-2018-5776
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
WordPress
4.9.2+
HIGH 8.8
CVE-2017-17091EPSS 7%
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remo…
WordPress
after 4.9
MEDIUM 5.4
CVE-2017-17092
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote…
WordPress
4.9.1+
MEDIUM 5.4
CVE-2017-17093
wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attack…
WordPress
4.9.1+