Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-16222 WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting … WordPress 5.2.3+ Fix from $1,6002019-09-11 MEDIUM 5.4 CVE-2019-16223EPSS 5% WordPress before 5.2.3 allows XSS in post previews by authenticated users. WordPress 5.2.3+ Fix from $1,6002019-09-11 MEDIUM 6.1 CVE-2019-16217 WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. WordPress 5.2.3+ Fix from $1,6002019-09-11 MEDIUM 6.1 CVE-2019-16218 WordPress before 5.2.3 allows XSS in stored comments. WordPress 5.2.3+ Fix from $1,6002019-09-11 MEDIUM 6.1 CVE-2019-16219 WordPress before 5.2.3 allows XSS in shortcode previews. WordPress 5.2.3+ Fix from $1,6002019-09-11 MEDIUM 6.1 CVE-2019-16220 In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect i… WordPress 5.2.3+ Fix from $1,6002019-09-11 MEDIUM 5.3 CVE-2017-6514 WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/o… WordPress Mitigation only Fix from $1,6002019-05-22 HIGH 8.8 CVE-2019-9787EPSS 41% WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration… WordPress 5.1.1+ Fix from $1,9502019-03-14 HIGH 8.8 CVE-2019-8942EPSS 83% WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary … WordPress 4.9.9+ Fix from $1,9502019-02-20 MEDIUM 6.5 CVE-2019-8943EPSS 93% WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an … WordPress after 5.0.3 Fix from $1,6002019-02-20 CRITICAL 9.8 CVE-2018-20148EPSS 27% In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XML… WordPress 4.9.9 / 5.0.1+ Fix from $2,3002018-12-14 HIGH 7.5 CVE-2018-20151EPSS 6% In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration w… WordPress 4.9.9 / 5.0.1+ Fix from $1,9502018-12-14 MEDIUM 6.5 CVE-2018-20147 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files. WordPress 4.9.9 / 5.0.1+ Fix from $1,6002018-12-14 MEDIUM 6.5 CVE-2018-20152 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input. WordPress 4.9.9 / 5.0.1+ Fix from $1,6002018-12-14 MEDIUM 6.1 CVE-2018-20150 In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. WordPress 4.9.9 / 5.0.1+ Fix from $1,6002018-12-14 MEDIUM 5.4 CVE-2018-20149 In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME typ… WordPress 4.9.9 / 5.0.1+ Fix from $1,6002018-12-14 MEDIUM 5.4 CVE-2018-20153 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. WordPress 4.9.9 / 5.0.1+ Fix from $1,6002018-12-14 HIGH 8.8 CVE-2018-1000773EPSS 8% WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution… WordPress after 4.9.8 Fix from $1,9502018-09-06 HIGH 8.8 CVE-2017-1000600 WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack… WordPress 4.9+ Fix from $1,9502018-09-06 HIGH 7.2 CVE-2018-14028EPSS 15% In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP fil… WordPress Patch available Fix from $1,9502018-08-10 HIGH 8.8 CVE-2018-12895EPSS 63% WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, whi… WordPress 4.9.7+ Fix from $1,9502018-06-26 MEDIUM 6.1 CVE-2018-10100 Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS. WordPress 4.9.5+ Fix from $1,6002018-04-16 MEDIUM 6.1 CVE-2018-10101 Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server. WordPress 4.9.5+ Fix from $1,6002018-04-16 MEDIUM 6.1 CVE-2018-10102 Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag. WordPress 4.9.5+ Fix from $1,6002018-04-16 HIGH 8.1 CVE-2014-6412 WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach. WordPress 4.4.0+ Fix from $1,9502018-04-12 HIGH 7.5 CVE-2018-6389EPSS 73% In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js … WordPress after 4.9.2 Fix from $1,9502018-02-06 MEDIUM 6.1 CVE-2018-5776 WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). WordPress 4.9.2+ Fix from $1,6002018-01-18 HIGH 8.8 CVE-2017-17091EPSS 7% wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remo… WordPress after 4.9 Fix from $1,9502017-12-02 MEDIUM 5.4 CVE-2017-17092 wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote… WordPress 4.9.1+ Fix from $1,6002017-12-02 MEDIUM 5.4 CVE-2017-17093 wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attack… WordPress 4.9.1+ Fix from $1,6002017-12-02