Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2017-17094 wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct X… WordPress 4.9.1+ Fix from $1,6002017-12-02 CRITICAL 9.8 CVE-2017-16510EPSS 7% WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQ… WordPress after 4.8.2 Fix from $2,3002017-11-02 HIGH 7.5 CVE-2012-6707 WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by levera… WordPress after 4.8.2 Fix from $1,9502017-10-19 MEDIUM 6.5 CVE-2017-14990 WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which mig… WordPress No fix yet Fix from $1,6002017-10-03 CRITICAL 9.8 CVE-2017-14723EPSS 7% Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the po… WordPress after 4.8.1 Fix from $2,3002017-09-23 HIGH 7.5 CVE-2017-14719EPSS 14% Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components. WordPress Patch available Fix from $1,9502017-09-23 HIGH 7.5 CVE-2017-14722EPSS 8% Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename. WordPress Patch available Fix from $1,9502017-09-23 MEDIUM 6.1 CVE-2017-14718 Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL. WordPress after 4.8.1 Fix from $1,6002017-09-23 MEDIUM 6.1 CVE-2017-14720 Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name. WordPress after 4.8.1 Fix from $1,6002017-09-23 MEDIUM 6.1 CVE-2017-14721 Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name. WordPress after 4.8.1 Fix from $1,6002017-09-23 MEDIUM 6.1 CVE-2017-14724 Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery. WordPress after 4.8.1 Fix from $1,6002017-09-23 MEDIUM 6.1 CVE-2017-14726 Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor. WordPress after 4.8.1 Fix from $1,6002017-09-23 MEDIUM 5.4 CVE-2017-14725 Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php. WordPress after 4.8.1 Fix from $1,6002017-09-23 HIGH 8.8 CVE-2017-9064 In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not requi… WordPress after 4.7.4 Fix from $1,9502017-05-18 HIGH 8.6 CVE-2017-9062 In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. WordPress after 4.7.4 Fix from $1,9502017-05-18 HIGH 8.6 CVE-2017-9066 In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF. WordPress after 4.7.4 Fix from $1,9502017-05-18 HIGH 7.5 CVE-2017-9065 In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API. WordPress after 4.7.4 Fix from $1,9502017-05-18 MEDIUM 6.1 CVE-2017-9061 In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message do… WordPress after 4.7.4 Fix from $1,6002017-05-18 MEDIUM 6.1 CVE-2017-9063 In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session. WordPress after 4.7.4 Fix from $1,6002017-05-18 MEDIUM 5.9 CVE-2017-8295EPSS 27% WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbit… WordPress after 4.7.4 Fix from $1,6002017-05-04 HIGH 7.5 CVE-2017-1001000EPSS 85% The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 doe… WordPress Patch available Fix from $1,9502017-04-03 MEDIUM 6.5 CVE-2017-6819 In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive… WordPress after 4.7.2 Fix from $1,6002017-03-12 MEDIUM 6.1 CVE-2017-6815 In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation. WordPress after 4.7.2 Fix from $1,6002017-03-12 MEDIUM 6.1 CVE-2017-6818 In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names. WordPress after 4.7.2 Fix from $1,6002017-03-12 MEDIUM 5.4 CVE-2017-6814 In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of… WordPress after 4.7.2 Fix from $1,6002017-03-12 MEDIUM 5.4 CVE-2017-6817 In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds. WordPress after 4.7.2 Fix from $1,6002017-03-12 CRITICAL 9.8 CVE-2017-5611EPSS 10% SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL … WordPress after 4.7.1 Fix from $2,3002017-01-30 MEDIUM 6.1 CVE-2017-5612 Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows … WordPress after 4.7.1 Fix from $1,6002017-01-30 MEDIUM 5.3 CVE-2017-5610EPSS 5% wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user… WordPress after 4.7.1 Fix from $1,6002017-01-30 HIGH 7.1 CVE-2016-6896EPSS 38% Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authen… WordPress No fix yet Fix from $1,9502017-01-18