CVEs (355)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress before 5.2.3 allows XSS in post previews by authenticated users. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows reflected XSS in the dashboard. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows XSS in shortcode previews. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows XSS in stored comments. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. |
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring. |
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search...Show more |
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Feb 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-m...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// U...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files. |
4Debian FedoraprojectPhpmailer Project+1 more4Debian Linux FedoraPhpmailer+1 moreNov 21, 2024 Nov 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. |