Debian Wordpress vulnerabilities
360 known vulnerabilities affecting debian/wordpress.
Total CVEs
360
CISA KEV
0
Public exploits
67
Exploited in wild
3
Severity breakdown
CRITICAL21HIGH56MEDIUM201LOW82
Vulnerabilities
Page 10 of 18
CVE-2014-9033MEDIUMCVSS 6.8fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9033 [MEDIUM] CVE-2014-9033: wordpress - Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7...
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.
Scope: local
bookworm: resolved (fixed in 4.0.1+dfsg-1)
bullseye: resolved (fixed in 4.0.1+dfsg-1)
forky: resolved (fixed in 4.0.1+dfsg-1)
sid: resolved
debian
CVE-2014-9031MEDIUMCVSS 4.3fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9031 [MEDIUM] CVE-2014-9031: wordpress - Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPres...
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.
Scope: local
bookworm: resolved (fixed in 4.0.1+dfsg-1)
bullseye: res
debian
CVE-2014-9032MEDIUMCVSS 4.3fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9032 [MEDIUM] CVE-2014-9032: wordpress - Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordP...
Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.0.1+dfsg-1)
bullseye: resolved (fixed in 4.0.1+dfsg-1)
forky: resolved (fixed in 4.0.1+dfsg-1)
sid: re
debian
CVE-2014-5204MEDIUMCVSS 6.8fixed in wordpress 3.9.2+dfsg-1 (bookworm)2014
CVE-2014-5204 [MEDIUM] CVE-2014-5204: wordpress - wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces ...
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.
Scope: local
bookworm: resolved (fixed in 3.9.2+dfsg-1)
bullseye: resolved (fixed in 3.9.2+dfsg-1
debian
CVE-2014-9037MEDIUMCVSS 6.8fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9037 [MEDIUM] CVE-2014-9037: wordpress - WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4...
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
Scope: local
bookworm: resolved (fixed in 4.0.1+dfsg-1)
bullseye: resolved (fixed in 4.0.1+dfsg-1)
forky: resolved (fixed in 4.0.1+dfs
debian
CVE-2014-6412LOWCVSS 8.12014
CVE-2014-6412 [HIGH] CVE-2014-6412: wordpress - WordPress before 4.4 makes it easier for remote attackers to predict password-re...
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2014-5240LOWCVSS 2.1fixed in wordpress 3.9.2+dfsg-1 (bookworm)2014
CVE-2014-5240 [LOW] CVE-2014-5240: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPre...
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
Scope: local
bookworm: resolved (fixed in 3.9.2+dfsg-1)
bullseye: resolved (fixed in 3.9.2+dfsg-1)
fo
debian
CVE-2013-4338HIGHCVSS 7.5fixed in wordpress 3.6.1+dfsg-1 (bookworm)2013
CVE-2013-4338 [HIGH] CVE-2013-4338: wordpress - wp-includes/functions.php in WordPress before 3.6.1 does not properly determine ...
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.
Scope: local
bookworm: resolved (fixed in 3.6.1+dfsg-1)
bullseye: resolved (fixed in 3.6.1+dfsg-1)
forky: resolved (fixed in 3.6.1+dfsg-1)
sid: re
debian
CVE-2013-4339HIGHCVSS 7.5fixed in wordpress 3.6.1+dfsg-1 (bookworm)2013
CVE-2013-4339 [HIGH] CVE-2013-4339: wordpress - WordPress before 3.6.1 does not properly validate URLs before use in an HTTP red...
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
Scope: local
bookworm: resolved (fixed in 3.6.1+dfsg-1)
bullseye: resolved (fixed in 3.6.1+dfsg-1)
forky: resolved (fixed in 3.6.1+dfsg-1)
sid: resolved (fixed in 3.6.1+dfsg-1)
trixie:
debian
CVE-2013-0235MEDIUMCVSS 6.4PoCfixed in wordpress 3.5.1+dfsg-1 (bookworm)2013
CVE-2013-0235 [MEDIUM] CVE-2013-0235: wordpress - The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP re...
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.
Scope: local
bookworm: resolved (fixed in 3.5.1+dfsg-1)
bullseye: resolved (fixed in 3.5.1+dfsg-1)
forky: resolved (f
debian
CVE-2013-2204MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2204 [MEDIUM] CVE-2013-2204: wordpress - moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in ...
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string a
debian
CVE-2013-2199MEDIUMCVSS 6.4fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2199 [MEDIUM] CVE-2013-2199: wordpress - The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requ...
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
debian
CVE-2013-2201MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2201 [MEDIUM] CVE-2013-2201: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 al...
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2013-2173MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2173 [MEDIUM] CVE-2013-2173: wordpress - wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post ...
wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
sid: resolved (
debian
CVE-2013-2202MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2202 [MEDIUM] CVE-2013-2202: wordpress - WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oE...
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.
debian
CVE-2013-2203MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2203 [MEDIUM] CVE-2013-2203: wordpress - WordPress before 3.5.2, when the uploads directory forbids write access, allows ...
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
debian
CVE-2013-5738MEDIUMCVSS 4.3fixed in wordpress 3.6.1+dfsg-1 (bookworm)2013
CVE-2013-5738 [MEDIUM] CVE-2013-5738: wordpress - The get_allowed_mime_types function in wp-includes/functions.php in WordPress be...
The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.
Scope: local
bookworm: resolved (fixed in 3.6.1+dfsg-1)
bullseye:
debian
CVE-2013-2205MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2205 [MEDIUM] CVE-2013-2205: wordpress - The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestri...
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (
debian
CVE-2013-2200MEDIUMCVSS 4.0fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2200 [MEDIUM] CVE-2013-2200: wordpress - WordPress before 3.5.2 does not properly check the capabilities of roles, which ...
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
sid: resolved
debian
CVE-2013-0237MEDIUMCVSS 4.3fixed in wordpress 3.5.1+dfsg-1 (bookworm)2013
CVE-2013-0237 [MEDIUM] CVE-2013-0237: wordpress - Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload be...
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Scope: local
bookworm: resolved (fixed in 3.5.1+dfsg-1)
bullseye: resolved (fixed in 3.5.1+dfsg-1)
forky: resolved (fixed in 3.5.1+dfsg
debian