İçeriğe atla
Noroxi

wordpress kayıtları

wordpress üreticisine ait 665 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
4 · %0,6
Silahlaştırılmış
15 · %2,3
Pre-auth RCE
101
Düzeltme kaydı olan
%53,2
Yayından KEV’e ortanca
4 gün

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

665 kayıt
  • The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    phpmailer project · phpmailer30 Ara 2016

  • CVE-2026-63030
    72Bu hafta

    WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %10

    wordpress · wordpress17 Tem 2026

  • CVE-2026-87902
    69Bu hafta

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %22

    wordpress · wordpress22 Eyl 2026

  • CVE-2016-10045
    68Bu hafta

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e

    KritikCVSS 9,8SilahlaştırılmışEPSS %98

    phpmailer project · phpmailer30 Ara 2016

  • CVE-2019-8942
    60Bu hafta

    WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a

    YüksekCVSS 8,8SilahlaştırılmışEPSS %83

    wordpress · wordpress19 Şub 2019

  • CVE-2022-21661
    59Planlayın

    SQL injection in WordPress

    YüksekCVSS 7,5Kavram kanıtıEPSS %98

    wordpress · wordpress6 Oca 2022

  • CVE-2017-1001000
    55Planlayın

    The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before

    YüksekCVSS 7,5SilahlaştırılmışEPSS %85

    wordpress · wordpress2 Nis 2017

  • CVE-2026-60137
    55Planlayın

    WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

    OrtaCVSS 5,9KEVSilahlaştırılmışEPSS %6

    wordpress · wordpress17 Tem 2026

  • CVE-2019-8943
    54Planlayın

    WordPress through 5.0.3 allows Path Traversal in wp_crop_image().

    OrtaCVSS 6,5SilahlaştırılmışEPSS %93

    wordpress · wordpress19 Şub 2019

  • CVE-2018-12895
    54Planlayın

    WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb param

    YüksekCVSS 8,8SilahlaştırılmışEPSS %62

    wordpress · wordpress26 Haz 2018

  • CVE-2021-29447
    52Planlayın

    WordPress Authenticated XXE attack when installation is running PHP 8

    OrtaCVSS 6,5Kavram kanıtıEPSS %86

    wordpress · wordpress15 Nis 2021

  • CVE-2018-6389
    52Planlayın

    In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist

    YüksekCVSS 7,5Kavram kanıtıEPSS %73

    wordpress · wordpress6 Şub 2018

  • CVE-2021-44223
    48Planlayın

    WordPress before 5.8 lacks support for the Update URI plugin header.

    KritikCVSS 9,8İstismar yokEPSS %29

    wordpress · wordpress25 Kas 2021

  • CVE-2017-5487
    47Planlayın

    wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not prop

    OrtaCVSS 5,3Kavram kanıtıEPSS %87

    wordpress · wordpress14 Oca 2017

  • CVE-2019-9787
    47Planlayın

    WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf

    YüksekCVSS 8,8Kavram kanıtıEPSS %39

    wordpress · wordpress14 Mar 2019

  • CVE-2018-20148
    47Planlayın

    In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMedi

    KritikCVSS 9,8Kavram kanıtıEPSS %27

    wordpress · wordpress14 Ara 2018

  • CVE-2009-2335
    46Planlayın

    WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,

    OrtaCVSS 5,0SilahlaştırılmışEPSS %85

    wordpress · wordpress10 Tem 2009

  • CVE-2012-3576
    46Planlayın

    Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to ex

    KritikCVSS 10,0Kavram kanıtıEPSS %18

    wordpress · wordpress15 Haz 2012

  • CVE-2014-9034
    45Planlayın

    wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers

    OrtaCVSS 5,0Kavram kanıtıEPSS %83

    wordpress · wordpress25 Kas 2014

  • CVE-2023-2745
    45Planlayın

    WordPress Core < 6.2.1 - Directory Traversal

    OrtaCVSS 5,4Kavram kanıtıEPSS %80

    wordpress · wordpress17 May 2023

  • CVE-2024-4439
    45Planlayın

    WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t

    OrtaCVSS 6,1Kavram kanıtıEPSS %71

    wordpress · wordpress3 May 2024

  • CVE-2008-3362
    45Planlayın

    Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attacke

    KritikCVSS 10,0Kavram kanıtıEPSS %17

    giulio ganci · wp downloads manager30 Tem 2008

  • CVE-2012-3575
    45Planlayın

    Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitr

    KritikCVSS 10,0Kavram kanıtıEPSS %15

    rbx gallery · rbx gallery15 Haz 2012

  • CVE-2008-1059
    44Planlayın

    PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a

    YüksekCVSS 7,5Kavram kanıtıEPSS %48

    wordpress · sniplets plugin28 Şub 2008

  • CVE-2020-28032
    44Planlayın

    WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

    KritikCVSS 9,8Kavram kanıtıEPSS %16

    wordpress · wordpress2 Kas 2020