Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2012-3578EPSS 8% Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to e… Fcchat Widget after 2.2.13.1 Fix from $1,6002012-06-17 MEDIUM 6.8 CVE-2012-1936 The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user ses… WordPress after 3.3.1 Fix from $1,6002012-05-03 HIGH 10.0 CVE-2012-2399EPSS 9% Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager … WordPress after 3.3.1 Fix from $1,9502012-04-21 HIGH 10.0 CVE-2012-2400 Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors. WordPress after 3.3.1 Fix from $1,9502012-04-21 MEDIUM 5.5 CVE-2012-2402 wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate … WordPress after 3.3.1 Fix from $1,6002012-04-21 MEDIUM 5.0 CVE-2012-2401 Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain f… WordPress after 3.3.1 Fix from $1,6002012-04-21 MEDIUM 5.0 CVE-2012-0937EPSS 8% wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external My… WordPress after 3.3.1 Fix from $1,6002012-01-30 HIGH 7.5 CVE-2011-4899EPSS 9% wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is a… WordPress after 3.3.1 Fix from $1,9502012-01-30 MEDIUM 5.0 CVE-2011-4898EPSS 10% wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbna… WordPress after 3.3.1 Fix from $1,6002012-01-30 HIGH 7.5 CVE-2011-4669 SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remote attackers to execute arbit… Wordpress Users after 1.3 Fix from $1,9502011-12-02 MEDIUM 5.0 CVE-2011-3818 WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation… WordPress Mitigation only Fix from $1,6002011-09-24 HIGH 10.0 CVE-2011-3125 Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hard… WordPress Patch available Fix from $1,9502011-08-10 HIGH 9.3 CVE-2011-3129 The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unkn… WordPress Patch available Fix from $1,9502011-08-10 HIGH 7.5 CVE-2011-3130 wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardeni… WordPress Patch available Fix from $1,9502011-08-10 MEDIUM 5.8 CVE-2011-3127 WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML doc… WordPress Patch available Fix from $1,6002011-08-10 MEDIUM 5.0 CVE-2011-3126 WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. WordPress Patch available Fix from $1,6002011-08-10 MEDIUM 5.0 CVE-2011-3128 WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive d… WordPress Patch available Fix from $1,6002011-08-10 HIGH 10.0 CVE-2011-3122 Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security." WordPress Patch available Fix from $1,9502011-08-10 MEDIUM 6.0 CVE-2010-4257 SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to e… WordPress after 3.0.1 Fix from $1,6002010-12-07 MEDIUM 6.0 CVE-2009-3890EPSS 8% Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain confi… WordPress after 2.8.5 Fix from $1,6002009-11-17 HIGH 10.0 CVE-2009-2853 Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-… WordPress Patch available Fix from $1,9502009-08-18 MEDIUM 6.4 CVE-2009-2854 Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a d… WordPress after 2.8.2 Fix from $1,6002009-08-18 HIGH 7.5 CVE-2009-2762EPSS 20% wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the admini… WordPress after 2.8.3 Fix from $1,9502009-08-13 MEDIUM 5.0 CVE-2009-2335EPSS 85% WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which all… WordPress 2.8.1+ Fix from $1,6002009-07-10 MEDIUM 5.0 CVE-2009-2336EPSS 5% The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the u… WordPress 2.8.1+ Fix from $1,6002009-07-10 MEDIUM 5.0 CVE-2009-2431 WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading t… WordPress Patch available Fix from $1,6002009-07-10 MEDIUM 5.0 CVE-2009-2432 WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals… WordPress after 2.7.1 Fix from $1,6002009-07-10 HIGH 10.0 CVE-2008-6767 wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (applic… WordPress No fix yet Fix from $1,9502009-04-28 HIGH 8.5 CVE-2008-5695EPSS 12% wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which al… WordPress 1.3.2+ Fix from $1,9502008-12-19 HIGH 9.3 CVE-2008-4769EPSS 9% Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remo… WordPress after 2.3.3 Fix from $1,9502008-10-28