Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.8
CVE-2012-3578EPSS 8%
Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to e…
Fcchat Widget
after 2.2.13.1
MEDIUM 6.8
CVE-2012-1936
The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user ses…
WordPress
after 3.3.1
HIGH 10.0
CVE-2012-2399EPSS 9%
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager …
WordPress
after 3.3.1
HIGH 10.0
CVE-2012-2400
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
WordPress
after 3.3.1
MEDIUM 5.5
CVE-2012-2402
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate …
WordPress
after 3.3.1
MEDIUM 5.0
CVE-2012-2401
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain f…
WordPress
after 3.3.1
MEDIUM 5.0
CVE-2012-0937EPSS 8%
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external My…
WordPress
after 3.3.1
HIGH 7.5
CVE-2011-4899EPSS 9%
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is a…
WordPress
after 3.3.1
MEDIUM 5.0
CVE-2011-4898EPSS 10%
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbna…
WordPress
after 3.3.1
HIGH 7.5
CVE-2011-4669
SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remote attackers to execute arbit…
Wordpress Users
after 1.3
MEDIUM 5.0
CVE-2011-3818
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation…
WordPress
Mitigation only
HIGH 10.0
CVE-2011-3125
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hard…
WordPress
Patch available
HIGH 9.3
CVE-2011-3129
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unkn…
WordPress
Patch available
HIGH 7.5
CVE-2011-3130
wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardeni…
WordPress
Patch available
MEDIUM 5.8
CVE-2011-3127
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML doc…
WordPress
Patch available
MEDIUM 5.0
CVE-2011-3126
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.
WordPress
Patch available
MEDIUM 5.0
CVE-2011-3128
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive d…
WordPress
Patch available
HIGH 10.0
CVE-2011-3122
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."
WordPress
Patch available
MEDIUM 6.0
CVE-2010-4257
SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to e…
WordPress
after 3.0.1
MEDIUM 6.0
CVE-2009-3890EPSS 8%
Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain confi…
WordPress
after 2.8.5
HIGH 10.0
CVE-2009-2853
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-…
WordPress
Patch available
MEDIUM 6.4
CVE-2009-2854
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a d…
WordPress
after 2.8.2
HIGH 7.5
CVE-2009-2762EPSS 20%
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the admini…
WordPress
after 2.8.3
MEDIUM 5.0
CVE-2009-2335EPSS 85%
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which all…
WordPress
2.8.1+
MEDIUM 5.0
CVE-2009-2336EPSS 5%
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the u…
WordPress
2.8.1+
MEDIUM 5.0
CVE-2009-2431
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading t…
WordPress
Patch available
MEDIUM 5.0
CVE-2009-2432
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals…
WordPress
after 2.7.1
HIGH 10.0
CVE-2008-6767
wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (applic…
WordPress
No fix yet
HIGH 8.5
CVE-2008-5695EPSS 12%
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which al…
WordPress
1.3.2+
HIGH 9.3
CVE-2008-4769EPSS 9%
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remo…
WordPress
after 2.3.3