wordpress

412 tracked vulnerabilities.

CVE-2007-0540
WordPress < 2.0 - Denial of Service via Pingback Service Calls
Jan 29, 2007
EPSS 0.08
CVE-2007-0541
WordPress < 2.0 - Information Disclosure via Pingback Service
Jan 29, 2007
EPSS 0.01
CVE-2007-0262
WordPress 2.0.6-2.1Alpha 3 - Info Disclosure
Jan 16, 2007
EPSS 0.01
CVE-2007-0233
WordPress <= 2.0.6 - SQL Injection via tb_id Parameter
Jan 13, 2007
EPSS 0.11
CVE-2007-0106
WordPress < 2.0.6 - Cross-Site Scripting via CSRF Protection Scheme
Jan 09, 2007
EPSS 0.02
CVE-2007-0107
WordPress < 2.0.6 - SQL Injection via Multibyte Charset Bypass
Jan 09, 2007
EPSS 0.07
CVE-2007-0109
WordPress <= 2.0.5 - Information Disclosure via Login Error Messages
Jan 09, 2007
EPSS 0.01
CVE-2006-6808
WordPress 2.0.5 - Cross-Site Scripting via File Parameter in wp-admin/templates.php
Dec 28, 2006
EPSS 0.03
CVE-2006-6016 MEDIUM
WordPress < 2.0.4 - Authenticated Out-of-bounds Read via user_id Parameter
Nov 21, 2006
CVSS 6.5
EPSS 0.01
CVE-2006-6017 MEDIUM
WordPress < 2.0.5 - Authenticated Denial of Service via Malformed Serialized Object
Nov 21, 2006
CVSS 6.5
EPSS 0.03
CVE-2006-5705
WordPress < 2.0.5 - Authenticated Directory Traversal and Arbitrary File Write via Backup and Fragment Parameters
Nov 04, 2006
EPSS 0.05
CVE-2006-4743
WordPress 2.0.2-2.0.5 - Information Disclosure via Direct File Request
Sep 13, 2006
EPSS 0.01
CVE-2006-4028
WordPress < 2.0.4 - Unspecified Vulnerabilities
Aug 09, 2006
EPSS 0.06
CVE-2006-3389
WordPress 2.0.3 - Information Disclosure via Invalid Paged Parameter
Jul 06, 2006
EPSS 0.01
CVE-2006-3390
WordPress 2.0.3 - Information Disclosure via Direct Request to Core Directories
Jul 06, 2006
EPSS 0.01
CVE-2006-2702
WordPress 2.0.2 - IP Address Spoofing via PC_REMOTE_ADDR Header
May 31, 2006
EPSS 0.01
CVE-2006-2667
WordPress < 2.0.2 - Remote Code Execution via Profile Update Displayname Injection
May 30, 2006
EPSS 0.32
CVE-2006-1796
WordPress < 2.0 - Cross-Site Scripting via Request URI
Apr 17, 2006
EPSS 0.00
CVE-2006-1263
WordPress < 2.0.2 - Cross-Site Scripting
Mar 19, 2006
EPSS 0.00
CVE-2006-1012
WordPress 1.5.2 - SQL Injection via User-Agent Header
Mar 06, 2006
EPSS 0.02
CVE-2006-0985
WordPress <= 2.0.1 - Stored Cross-Site Scripting via Comment Parameters
Mar 03, 2006
EPSS 0.01
CVE-2006-0986
WordPress <= 2.0.1 - Information Disclosure via Direct Request to Sensitive Files
Mar 03, 2006
EPSS 0.02
CVE-2006-0733
WordPress 2.0.0 - Stored Cross-Site Scripting via Author Website Field
Feb 16, 2006
EPSS 0.01
CVE-2005-4463
WordPress < 1.5.2 - Information Disclosure via Direct Request to Sensitive Files
Dec 21, 2005
EPSS 0.02
CVE-2005-2612
WordPress <1.5.1.3 - Code Injection
Aug 17, 2005
EPSS 0.73