Перейти к содержимому
Noroxi

Записи WordPress

665 опубликованных записей вендора wordpress.

Профиль для исследователя

Попали в KEV
4 · 0,6 %
С эксплойтом
15 · 2,3 %
Pre-auth RCE
101
С записью об исправлении
53,2 %
Медиана: публикация → KEV
4 дн.

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

665 записей
  • CVE-2016-10033
    99Срочно

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    phpmailer project · phpmailer30 дек. 2016 г.

  • CVE-2026-63030
    72На этой неделе

    WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 10 %

    wordpress · wordpress17 июл. 2026 г.

  • CVE-2016-10045
    68На этой неделе

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e

    КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %

    phpmailer project · phpmailer30 дек. 2016 г.

  • CVE-2026-87902
    68На этой неделе

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 20 %

    wordpress · wordpress22 сент. 2026 г.

  • CVE-2019-8942
    60На этой неделе

    WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 83 %

    wordpress · wordpress19 февр. 2019 г.

  • CVE-2022-21661
    59В плане

    SQL injection in WordPress

    ВысокаяCVSS 7,5Proof of conceptEPSS 98 %

    wordpress · wordpress6 янв. 2022 г.

  • CVE-2017-1001000
    55В плане

    The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 85 %

    wordpress · wordpress2 апр. 2017 г.

  • CVE-2026-60137
    55В плане

    WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

    СредняяCVSS 5,9KEVГотовый эксплойтEPSS 6 %

    wordpress · wordpress17 июл. 2026 г.

  • CVE-2019-8943
    54В плане

    WordPress through 5.0.3 allows Path Traversal in wp_crop_image().

    СредняяCVSS 6,5Готовый эксплойтEPSS 93 %

    wordpress · wordpress19 февр. 2019 г.

  • CVE-2018-12895
    54В плане

    WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb param

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 62 %

    wordpress · wordpress26 июн. 2018 г.

  • CVE-2021-29447
    52В плане

    WordPress Authenticated XXE attack when installation is running PHP 8

    СредняяCVSS 6,5Proof of conceptEPSS 86 %

    wordpress · wordpress15 апр. 2021 г.

  • CVE-2018-6389
    52В плане

    In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist

    ВысокаяCVSS 7,5Proof of conceptEPSS 73 %

    wordpress · wordpress6 февр. 2018 г.

  • CVE-2021-44223
    48В плане

    WordPress before 5.8 lacks support for the Update URI plugin header.

    КритическаяCVSS 9,8Эксплойта нетEPSS 29 %

    wordpress · wordpress25 нояб. 2021 г.

  • CVE-2017-5487
    47В плане

    wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not prop

    СредняяCVSS 5,3Proof of conceptEPSS 87 %

    wordpress · wordpress14 янв. 2017 г.

  • CVE-2019-9787
    47В плане

    WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf

    ВысокаяCVSS 8,8Proof of conceptEPSS 39 %

    wordpress · wordpress14 мар. 2019 г.

  • CVE-2018-20148
    47В плане

    In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMedi

    КритическаяCVSS 9,8Proof of conceptEPSS 27 %

    wordpress · wordpress14 дек. 2018 г.

  • CVE-2009-2335
    46В плане

    WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,

    СредняяCVSS 5,0Готовый эксплойтEPSS 85 %

    wordpress · wordpress10 июл. 2009 г.

  • CVE-2012-3576
    46В плане

    Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to ex

    КритическаяCVSS 10,0Proof of conceptEPSS 18 %

    wordpress · wordpress15 июн. 2012 г.

  • CVE-2014-9034
    45В плане

    wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers

    СредняяCVSS 5,0Proof of conceptEPSS 83 %

    wordpress · wordpress25 нояб. 2014 г.

  • CVE-2023-2745
    45В плане

    WordPress Core < 6.2.1 - Directory Traversal

    СредняяCVSS 5,4Proof of conceptEPSS 80 %

    wordpress · wordpress17 мая 2023 г.

  • CVE-2024-4439
    45В плане

    WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t

    СредняяCVSS 6,1Proof of conceptEPSS 71 %

    wordpress · wordpress3 мая 2024 г.

  • CVE-2008-3362
    45В плане

    Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attacke

    КритическаяCVSS 10,0Proof of conceptEPSS 17 %

    giulio ganci · wp downloads manager30 июл. 2008 г.

  • CVE-2012-3575
    45В плане

    Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitr

    КритическаяCVSS 10,0Proof of conceptEPSS 15 %

    rbx gallery · rbx gallery15 июн. 2012 г.

  • CVE-2008-1059
    44В плане

    PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a

    ВысокаяCVSS 7,5Proof of conceptEPSS 48 %

    wordpress · sniplets plugin28 февр. 2008 г.

  • CVE-2020-28032
    44В плане

    WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

    КритическаяCVSS 9,8Proof of conceptEPSS 16 %

    wordpress · wordpress2 нояб. 2020 г.