Search

Found 284 results in 110ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-17094 medium 5.4 5.4 FIX debian debian wordpress 9y ago wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.
CVE-2017-17093 medium 5.4 5.4 FIX debian debian wordpress 9y ago wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language settin…
CVE-2017-17092 medium 5.4 5.4 FIX debian debian wordpress 9y ago wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted fi…
CVE-2017-16510 critical 9.8 9.8 FIX debian debian wordpress 9y ago WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "d…
CVE-2016-9263 medium 4.7 4.7 FIX debian debian wordpress 9y ago WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained wit…
CVE-2017-14990 medium 6.5 6.5 FIX debian debian wordpress 9y ago WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack u…
CVE-2017-14726 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
CVE-2017-14725 medium 5.4 5.4 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
CVE-2017-14724 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
CVE-2017-14723 critical 9.8 9.8 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injec…
CVE-2017-14721 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
CVE-2017-14720 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
CVE-2017-14718 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
CVE-2017-9063 medium 6.1 6.1 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
CVE-2017-9061 medium 6.1 6.1 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filen…
CVE-2017-8295 medium 5.9 6.9 EXPFIX debian debian wordpress 9y ago WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?ac…
CVE-2017-6819 medium 6.5 6.5 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an …
CVE-2017-6818 medium 6.1 6.1 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
CVE-2017-6817 medium 5.4 5.4 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
CVE-2017-6816 medium 4.9 4.9 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
CVE-2017-6815 medium 6.1 6.1 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
CVE-2017-6814 medium 5.4 5.4 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortco…
CVE-2017-5612 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or…
CVE-2017-5611 critical 9.8 9.8 FIX debian debian wordpressoracle 10y ago SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected…
CVE-2017-5610 medium 5.3 5.3 FIX debian debian wordpress 10y ago wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypas…
CVE-2016-6897 medium 6.5 7.5 EXPFIX debian debian wordpress 10y ago Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authenticatio…
CVE-2016-10148 medium 4.3 4.3 FIX debian debian wordpress 10y ago The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authen…
CVE-2017-5491 medium 5.3 5.3 FIX arch archdebian debian wordpress 10y ago wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
CVE-2017-5490 medium 6.1 6.1 FIX arch archdebian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or…
CVE-2017-5488 medium 6.1 6.1 FIX arch archdebian debian wordpress 10y ago Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version…
CVE-2017-5487 medium 5.3 6.3 EXPFIX arch archdebian debian wordpress 10y ago wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote…
CVE-2016-7169 medium 6.3 6.3 FIX arch archdebian debian wordpress 10y ago Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authent…
CVE-2016-7168 medium 4.8 4.8 FIX arch archdebian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HT…
CVE-2016-10045 critical 9.8 10.0 EXPFIX arch archdebian debian phpmailer_projectwordpressjoomla 10y ago Remote code execution in PHPMailer
CVE-2016-6634 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-5834 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HT…
CVE-2016-5833 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web scri…
CVE-2016-4567 medium 6.1 6.1 debian debian mediaelementjswordpress 10y ago MediaElement Vulnerable to Reflected XSS
CVE-2016-4566 medium 6.1 6.1 FIX debian debian wordpressplupload 10y ago Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-O…
CVE-2016-1564 medium 6.1 6.1 FIX debian debian wordpress 10y ago Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name…
CVE-2015-8834 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored…
CVE-2015-7989 medium 5.4 5.4 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a diff…
CVE-2015-5715 medium 4.3 4.3 FIX debian debian wordpress 10y ago The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arra…
CVE-2015-5714 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during proces…
CVE-2015-5734 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML v…
CVE-2015-5733 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script…
CVE-2015-5732 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary …
CVE-2015-5731 medium 6.8 FIX debian debian wordpress 11y ago Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, an…
CVE-2015-5730 medium 5.0 FIX debian debian wordpress 11y ago The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to con…
CVE-2015-3439 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, all…
CVE-2015-3438 medium 4.3 FIX debian debian wordpress 11y ago Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byt…
CVE-2015-5623 medium 4.0 FIX debian debian wordpress 11y ago WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscribe…
CVE-2015-3440 medium 5.3 EXPFIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored…
CVE-2015-3429 medium 4.3 FIX debian debian automatticwordpress 11y ago Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment i…
CVE-2014-9039 medium 4.3 FIX debian debian wordpress 12y ago wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that rec…
CVE-2014-9038 medium 6.4 FIX debian debian wordpress 12y ago wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring…
CVE-2014-9037 medium 6.8 FIX debian debian wordpress 12y ago WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic …
CVE-2014-9036 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a c…
CVE-2014-9035 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script o…
CVE-2014-9034 medium 6.0 EXPFIX debian debian wordpress 12y ago wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long …
CVE-2014-9033 medium 6.8 FIX debian debian wordpress 12y ago Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that res…
CVE-2014-9032 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via …
CVE-2014-9031 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HT…
CVE-2014-5266 medium 6.0 EXPFIX debian debian wordpressdrupal 12y ago The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote atta…
CVE-2014-5265 medium 5.0 FIX debian debian drupalwordpress 12y ago The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion,…
CVE-2014-5205 medium 6.8 FIX debian debian wordpress 12y ago wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a…
CVE-2014-5204 medium 6.8 FIX debian debian wordpress 12y ago wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote atta…
CVE-2014-4534 medium 4.3 html5_video_player_with_playlist_plugin_projectwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitra…
CVE-2014-4603 medium 4.3 yahoo\!_updates_for_wordpress_plugin_projectwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web…
CVE-2014-4600 medium 4.3 wp_ultimate_email_marketer_projectwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script …
CVE-2014-4529 medium 4.3 flash_photo_gallery_projectwordpress 12y ago Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path…
CVE-2012-4915 medium 6.0 EXP davistribewordpress 12y ago Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.
CVE-2014-3845 medium 6.8 tinymcewordpress 12y ago Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that…
CVE-2014-3844 medium 5.0 tinymcewordpress 12y ago The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOTE: some of these det…
CVE-2014-3843 medium 6.8 zemantawordpress 12y ago Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vect…
CVE-2014-3841 medium 4.3 tech-bankerwordpress 12y ago Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Label field, related to form lay…
CVE-2014-3210 medium 7.5 EXP dotonpaperwordpress 12y ago SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via…
CVE-2013-2706 medium 6.8 rodrigo_polowordpress 12y ago Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change p…
CVE-2014-0166 medium 6.4 FIX debian debian wordpress 12y ago The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it e…
CVE-2014-0165 medium 4.0 FIX debian debian wordpress 12y ago WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-…
CVE-2012-4920 medium 5.0 zingiriwordpress 12y ago Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files vi…
CVE-2013-0734 medium 4.3 cartpaujwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words param…
CVE-2014-2265 medium 5.0 rocklobsterwordpress 12y ago Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 paramet…
CVE-2014-2315 medium 4.3 shinephpwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.8.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) thanks_caption…
CVE-2014-1907 medium 7.4 EXP videowhisperwordpress 12y ago Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in…
CVE-2013-3487 medium 4.3 ait-prowordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in the security log in the BulletProof Security plugin before .49 for WordPress allow remote attackers to inject arbitrary web script or HTML via u…
CVE-2013-1409 medium 5.3 EXP commentluvwordpress 12y ago Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/…
CVE-2014-1888 medium 4.3 buddypresswordpress 12y ago Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/crea…
CVE-2012-6635 medium 4.0 FIX debian debian wordpress 13y ago wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by vi…
CVE-2012-6634 medium 6.4 FIX debian debian wordpress 13y ago wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
CVE-2012-6633 medium 4.3 FIX debian debian wordpress 13y ago Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
CVE-2011-5270 medium 4.0 FIX debian debian wordpress 13y ago wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contr…
CVE-2010-5296 medium 4.9 FIX debian debian wordpress 13y ago wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticate…
CVE-2010-5295 medium 4.3 FIX debian debian wordpress 13y ago Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is no…
CVE-2010-5294 medium 4.3 FIX debian debian wordpress 13y ago Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web…
CVE-2010-5293 medium 5.8 FIX debian debian wordpress 13y ago wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafte…
CVE-2014-1232 medium 4.3 foliovisionwordpress 13y ago Cross-site scripting (XSS) vulnerability in the Foliopress WYSIWYG plugin before 2.6.8.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-7279 medium 4.3 anthony_millswordpress 13y ago Cross-site scripting (XSS) vulnerability in views/video-management/preview_video.php in the S3 Video plugin before 0.983 for WordPress allows remote attackers to inject arbitrary web script or HTML v…
CVE-2013-7276 medium 4.3 recommend_to_a_friend_projectwordpress 13y ago Cross-site scripting (XSS) vulnerability in inc/raf_form.php in the Recommend to a friend plugin 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the current_url…
CVE-2013-7240 medium 6.0 EXP westerndealwordpress 13y ago Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.