wordpress kayıtları
wordpress üreticisine ait 665 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %0,6
- Silahlaştırılmış
- 15 · %2,3
- Pre-auth RCE
- 101
- Düzeltme kaydı olan
- %53,2
- Yayından KEV’e ortanca
- 4 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')235
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')58
- CWE-352 Cross-Site Request Forgery (CSRF)53
- CWE-264 Permissions, Privileges, and Access Controls41
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor30
- CWE-20 Improper Input Validation24
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
665 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2016-10033Silahlaştırılmış | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Kritik9,8 | KEV | %99,7 | 30 Ara 2016 |
72Bu hafta | CVE-2026-63030Silahlaştırılmış | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Executionwordpress · wordpress · CWE-436 | Kritik9,8 | KEV | %10,1 | 17 Tem 2026 |
69Bu hafta | CVE-2026-87902Silahlaştırılmış | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the wordpress · wordpress · CWE-98 | Yüksek8,1 | KEV | %22,5 | 22 Eyl 2026 |
68Bu hafta | CVE-2016-10045Silahlaştırılmış | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently ephpmailer project · phpmailer · CWE-77 | Kritik9,8 | — | %97,7 | 30 Ara 2016 |
60Bu hafta | CVE-2019-8942Silahlaştırılmış | WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an awordpress · wordpress · CWE-434 | Yüksek8,8 | — | %82,7 | 19 Şub 2019 |
59Planlayın | CVE-2022-21661Kavram kanıtı | SQL injection in WordPresswordpress · wordpress · CWE-89 | Yüksek7,5 | — | %97,8 | 6 Oca 2022 |
55Planlayın | CVE-2017-1001000Silahlaştırılmış | The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before wordpress · wordpress | Yüksek7,5 | — | %84,9 | 2 Nis 2017 |
55Planlayın | CVE-2026-60137Silahlaştırılmış | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Querywordpress · wordpress · CWE-89 | Orta5,9 | KEV | %5,9 | 17 Tem 2026 |
54Planlayın | CVE-2019-8943Silahlaştırılmış | WordPress through 5.0.3 allows Path Traversal in wp_crop_image().wordpress · wordpress · CWE-22 | Orta6,5 | — | %92,6 | 19 Şub 2019 |
54Planlayın | CVE-2018-12895Silahlaştırılmış | WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb paramwordpress · wordpress · CWE-22 | Yüksek8,8 | — | %62,2 | 26 Haz 2018 |
52Planlayın | CVE-2021-29447Kavram kanıtı | WordPress Authenticated XXE attack when installation is running PHP 8wordpress · wordpress · CWE-611 | Orta6,5 | — | %85,7 | 15 Nis 2021 |
52Planlayın | CVE-2018-6389Kavram kanıtı | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registwordpress · wordpress · CWE-400 | Yüksek7,5 | — | %72,7 | 6 Şub 2018 |
48Planlayın | CVE-2021-44223İstismar yok | WordPress before 5.8 lacks support for the Update URI plugin header.wordpress · wordpress | Kritik9,8 | — | %29,0 | 25 Kas 2021 |
47Planlayın | CVE-2017-5487Kavram kanıtı | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not propwordpress · wordpress · CWE-200 | Orta5,3 | — | %87,3 | 14 Oca 2017 |
47Planlayın | CVE-2019-9787Kavram kanıtı | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default confwordpress · wordpress · CWE-352 | Yüksek8,8 | — | %38,7 | 14 Mar 2019 |
47Planlayın | CVE-2018-20148Kavram kanıtı | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediwordpress · wordpress · CWE-502 | Kritik9,8 | — | %26,8 | 14 Ara 2018 |
46Planlayın | CVE-2009-2335Silahlaştırılmış | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, wordpress · wordpress · CWE-16 | Orta5,0 | — | %85,0 | 10 Tem 2009 |
46Planlayın | CVE-2012-3576Kavram kanıtı | Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to exwordpress · wordpress · CWE-264 | Kritik10,0 | — | %18,4 | 15 Haz 2012 |
45Planlayın | CVE-2014-9034Kavram kanıtı | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackerswordpress · wordpress · CWE-19 | Orta5,0 | — | %82,7 | 25 Kas 2014 |
45Planlayın | CVE-2023-2745Kavram kanıtı | WordPress Core < 6.2.1 - Directory Traversalwordpress · wordpress · CWE-22 | Orta5,4 | — | %79,5 | 17 May 2023 |
45Planlayın | CVE-2024-4439Kavram kanıtı | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due twordpress · wordpress · CWE-80 | Orta6,1 | — | %71,0 | 3 May 2024 |
45Planlayın | CVE-2008-3362Kavram kanıtı | Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackegiulio ganci · wp downloads manager · CWE-20 | Kritik10,0 | — | %16,8 | 30 Tem 2008 |
45Planlayın | CVE-2012-3575Kavram kanıtı | Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrrbx gallery · rbx gallery · CWE-264 | Kritik10,0 | — | %15,4 | 15 Haz 2012 |
44Planlayın | CVE-2008-1059Kavram kanıtı | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote awordpress · sniplets plugin · CWE-94 | Yüksek7,5 | — | %48,3 | 28 Şub 2008 |
44Planlayın | CVE-2020-28032Kavram kanıtı | WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.wordpress · wordpress · CWE-502 | Kritik9,8 | — | %16,1 | 2 Kas 2020 |
- CVE-2016-1003399Hemen
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100phpmailer project · phpmailer30 Ara 2016
- CVE-2026-6303072Bu hafta
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %10wordpress · wordpress17 Tem 2026
- CVE-2026-8790269Bu hafta
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %22wordpress · wordpress22 Eyl 2026
- CVE-2016-1004568Bu hafta
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e
KritikCVSS 9,8SilahlaştırılmışEPSS %98phpmailer project · phpmailer30 Ara 2016
- CVE-2019-894260Bu hafta
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a
YüksekCVSS 8,8SilahlaştırılmışEPSS %83wordpress · wordpress19 Şub 2019
- CVE-2022-2166159Planlayın
SQL injection in WordPress
YüksekCVSS 7,5Kavram kanıtıEPSS %98wordpress · wordpress6 Oca 2022
- CVE-2017-100100055Planlayın
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before
YüksekCVSS 7,5SilahlaştırılmışEPSS %85wordpress · wordpress2 Nis 2017
- CVE-2026-6013755Planlayın
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
OrtaCVSS 5,9KEVSilahlaştırılmışEPSS %6wordpress · wordpress17 Tem 2026
- CVE-2019-894354Planlayın
WordPress through 5.0.3 allows Path Traversal in wp_crop_image().
OrtaCVSS 6,5SilahlaştırılmışEPSS %93wordpress · wordpress19 Şub 2019
- CVE-2018-1289554Planlayın
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb param
YüksekCVSS 8,8SilahlaştırılmışEPSS %62wordpress · wordpress26 Haz 2018
- CVE-2021-2944752Planlayın
WordPress Authenticated XXE attack when installation is running PHP 8
OrtaCVSS 6,5Kavram kanıtıEPSS %86wordpress · wordpress15 Nis 2021
- CVE-2018-638952Planlayın
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist
YüksekCVSS 7,5Kavram kanıtıEPSS %73wordpress · wordpress6 Şub 2018
- CVE-2021-4422348Planlayın
WordPress before 5.8 lacks support for the Update URI plugin header.
KritikCVSS 9,8İstismar yokEPSS %29wordpress · wordpress25 Kas 2021
- CVE-2017-548747Planlayın
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not prop
OrtaCVSS 5,3Kavram kanıtıEPSS %87wordpress · wordpress14 Oca 2017
- CVE-2019-978747Planlayın
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf
YüksekCVSS 8,8Kavram kanıtıEPSS %39wordpress · wordpress14 Mar 2019
- CVE-2018-2014847Planlayın
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMedi
KritikCVSS 9,8Kavram kanıtıEPSS %27wordpress · wordpress14 Ara 2018
- CVE-2009-233546Planlayın
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,
OrtaCVSS 5,0SilahlaştırılmışEPSS %85wordpress · wordpress10 Tem 2009
- CVE-2012-357646Planlayın
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to ex
KritikCVSS 10,0Kavram kanıtıEPSS %18wordpress · wordpress15 Haz 2012
- CVE-2014-903445Planlayın
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers
OrtaCVSS 5,0Kavram kanıtıEPSS %83wordpress · wordpress25 Kas 2014
- CVE-2023-274545Planlayın
WordPress Core < 6.2.1 - Directory Traversal
OrtaCVSS 5,4Kavram kanıtıEPSS %80wordpress · wordpress17 May 2023
- CVE-2024-443945Planlayın
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t
OrtaCVSS 6,1Kavram kanıtıEPSS %71wordpress · wordpress3 May 2024
- CVE-2008-336245Planlayın
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attacke
KritikCVSS 10,0Kavram kanıtıEPSS %17giulio ganci · wp downloads manager30 Tem 2008
- CVE-2012-357545Planlayın
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitr
KritikCVSS 10,0Kavram kanıtıEPSS %15rbx gallery · rbx gallery15 Haz 2012
- CVE-2008-105944Planlayın
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a
YüksekCVSS 7,5Kavram kanıtıEPSS %48wordpress · sniplets plugin28 Şub 2008
- CVE-2020-2803244Planlayın
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
KritikCVSS 9,8Kavram kanıtıEPSS %16wordpress · wordpress2 Kas 2020