Wordpress
wordpress
409 CVEs • 51 products
Products (51)
Click to collapseToggle
Products (51)
Click to collapse
CVEs (409)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress before 5.2.3 allows XSS in post previews by authenticated users. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows reflected XSS in the dashboard. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows XSS in shortcode previews. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows XSS in stored comments. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. |
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring. |
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search...Show more |
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Feb 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input. |