wordpress

412 tracked vulnerabilities.

CVE-2008-0192
WordPress < 2.0.9 - Cross-Site Scripting via popuptitle Parameter
Jan 10, 2008
EPSS 0.02
CVE-2008-0193
WordPress < 2.0.11 - Cross-Site Scripting via Backup Parameter
Jan 10, 2008
EPSS 0.02
CVE-2008-0194
WordPress < 2.0.3 - Path Traversal and Arbitrary File Read/Delete via Backup Parameter
Jan 10, 2008
EPSS 0.01
CVE-2008-0195
WordPress < 2.0.11 - Unauthenticated Sensitive Information Exposure via Empty Page Parameter
Jan 10, 2008
EPSS 0.02
CVE-2008-0196
WordPress < 2.0.11 - Path Traversal and Arbitrary File Write via Page and Import Parameters
Jan 10, 2008
EPSS 0.00
CVE-2008-0197
WP-ContactForm < 1.5_alpha - Cross-Site Scripting via Multiple Parameters
Jan 10, 2008
EPSS 0.00
CVE-2008-0203
Cryptographp < 1.2 - Stored Cross-Site Scripting via Multiple Parameters
Jan 10, 2008
EPSS 0.00
CVE-2008-0204
Math Comment Spam Protection Plugin < 2.1 - Cross-Site Scripting via Parameters
Jan 10, 2008
EPSS 0.00
CVE-2008-0205
Math Comment Spam Protection Plugin < 2.1 - Cross-Site Request Forgery
Jan 10, 2008
EPSS 0.00
CVE-2008-0206
WordPress Captcha Plugin < 2.5d - Cross-Site Scripting via captcha_ttffolder Parameter
Jan 10, 2008
EPSS 0.00
CVE-2007-6369
PictPress < 0.91 - Path Traversal via Size or Path Parameter
Dec 15, 2007
EPSS 0.03
CVE-2007-6318
WordPress <= 2.3.1 - SQL Injection via s Parameter
Dec 12, 2007
EPSS 0.04
CVE-2007-6013 CRITICAL
WordPress 1.5-2.3.1 - Authentication Bypass via MD5 Hash Reuse
Nov 19, 2007
CVSS 9.8
EPSS 0.02
CVE-2007-5710
WordPress 2.3 - Cross-Site Scripting via posts_columns Array Parameter
Oct 30, 2007
EPSS 0.03
CVE-2007-5105
WordPress 2.0-2.0.1 - Cross-Site Scripting via user_email Parameter
Sep 26, 2007
EPSS 0.02
CVE-2007-5106
WordPress 2.0 - Cross-Site Scripting via wp-register.php user_login Parameter
Sep 26, 2007
EPSS 0.00
CVE-2007-4893
WordPress < 2.2.3 and WordPress MU < 1.2.5a - Cross-Site Scripting via Unfiltered HTML Privilege
Sep 14, 2007
EPSS 0.02
CVE-2007-4894
WordPress < 2.2.3 and WordPress MU < 1.2.5a - SQL Injection via XMLRPC Pingback Post Type Parameter
Sep 14, 2007
EPSS 0.04
CVE-2007-4544
WordPress MU < 1.0 - Cross-Site Scripting via Weblog ID Parameter
Aug 27, 2007
EPSS 0.00
CVE-2007-4480
Sirius 1.0 - Cross-Site Scripting via PATH_INFO
Aug 22, 2007
EPSS 0.00
CVE-2007-4481
Blix 0.9.1 - Cross-Site Scripting via PATH_INFO
Aug 22, 2007
EPSS 0.00
CVE-2007-4482
WordPress Pool 1.0.7 - Cross-Site Scripting via PATH_INFO
Aug 22, 2007
EPSS 0.01
CVE-2007-4483
WordPress Classic 1.5 - Cross-Site Scripting via PATH_INFO
Aug 22, 2007
EPSS 0.01
CVE-2007-4166
Unnamed theme <1.217 & SE <1.02 - XSS
Aug 07, 2007
EPSS 0.01
CVE-2007-4153
WordPress 2.2.1 - Authenticated Stored Cross-Site Scripting via Admin Panel Options Database Table or OPML URL Import
Aug 03, 2007
EPSS 0.00