cbcvebase.

Debian Wordpress vulnerabilities

333 known vulnerabilities affecting debian/wordpress.

Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57

Vulnerabilities

Page 11 of 17
CVE-2017-14718P4MEDIUMCVSS 6.1fixed in wordpress 4.8.2+dfsg-1 (bookworm)2017
CVE-2017-14718 [MEDIUM] CVE-2017-14718: wordpress - Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack... Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL. Scope: local bookworm: resolved (fixed in 4.8.2+dfsg-1) bullseye: resolved (fixed in 4.8.2+dfsg-1) forky: resolved (fixed in 4.8.2+dfsg-1) sid: resolved (fixed in 4.8.2+dfsg-1) trixie: resolved (fixed in 4.8.2+dfsg-1)
debian
CVE-2018-5776P4MEDIUMCVSS 6.1fixed in wordpress 4.9.2+dfsg-1 (bookworm)2018
CVE-2018-5776 [MEDIUM] CVE-2018-5776: wordpress - WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (unde... WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). Scope: local bookworm: resolved (fixed in 4.9.2+dfsg-1) bullseye: resolved (fixed in 4.9.2+dfsg-1) forky: resolved (fixed in 4.9.2+dfsg-1) sid: resolved (fixed in 4.9.2+dfsg-1) trixie: resolved (fixed in 4.9.2+dfsg-1)
debian
CVE-2020-11030P4MEDIUMCVSS 6.4fixed in wordpress 5.4.1+dfsg1-1 (bookworm)2020
CVE-2020-11030 [MEDIUM] CVE-2020-11030: wordpress - In affected versions of WordPress, a special payload can be crafted that can lea... In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9
debian
CVE-2016-5833P4MEDIUMCVSS 6.1fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5833 [MEDIUM] CVE-2016-5833: wordpress - Cross-site scripting (XSS) vulnerability in the column_title function in wp-admi... Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834. Scope: local bookworm: resolved (fixed in 4.5.3+dfsg-1) bullseye: resolved (fix
debian
CVE-2019-16219P4MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16219 [MEDIUM] CVE-2019-16219: wordpress - WordPress before 5.2.3 allows XSS in shortcode previews. WordPress before 5.2.3 allows XSS in shortcode previews. Scope: local bookworm: resolved (fixed in 5.2.3+dfsg1-1) bullseye: resolved (fixed in 5.2.3+dfsg1-1) forky: resolved (fixed in 5.2.3+dfsg1-1) sid: resolved (fixed in 5.2.3+dfsg1-1) trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2018-20153P4MEDIUMCVSS 5.4fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20153 [MEDIUM] CVE-2018-20153: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new co... In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. Scope: local bookworm: resolved (fixed in 5.0.1+dfsg1-1) bullseye: resolved (fixed in 5.0.1+dfsg1-1) forky: resolved (fixed in 5.0.1+dfsg1-1) sid: resolved (fixed in 5.0.1+dfsg1-1) trixie: resolved (fixed in 5.0.1+df
debian
CVE-2017-17094P4MEDIUMCVSS 5.4fixed in wordpress 4.9.1+dfsg-1 (bookworm)2017
CVE-2017-17094 [MEDIUM] CVE-2017-17094: wordpress - wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclos... wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL. Scope: local bookworm: resolved (fixed in 4.9.1+dfsg-1) bullseye: resolved (fixed in 4.9.1+dfsg-1) forky: resolved (fixed in 4.9.1+dfsg-1) sid: resolved (fixed in 4.9.1+dfsg-1) trixie:
debian
CVE-2019-17674P4MEDIUMCVSS 5.4fixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17674 [MEDIUM] CVE-2019-17674: wordpress - WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via th... WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. Scope: local bookworm: resolved (fixed in 5.2.4+dfsg1-1) bullseye: resolved (fixed in 5.2.4+dfsg1-1) forky: resolved (fixed in 5.2.4+dfsg1-1) sid: resolved (fixed in 5.2.4+dfsg1-1) trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2014-5265P4MEDIUMCVSS 6.5fixed in wordpress 3.9.2+dfsg-1 (bookworm)2014
CVE-2014-5265 [MEDIUM] CVE-2014-5265: wordpress - The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal ... The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity referenc
debian
CVE-2015-8834P4MEDIUMCVSS 4.3fixed in wordpress 4.2.2+dfsg-1 (bookworm)2015
CVE-2015-8834 [MEDIUM] CVE-2015-8834: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress b... Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3440. Scope: local bookworm: resolved (f
debian
CVE-2017-14724P4MEDIUMCVSS 6.1fixed in wordpress 4.8.2+dfsg-1 (bookworm)2017
CVE-2017-14724 [MEDIUM] CVE-2017-14724: wordpress - Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed... Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery. Scope: local bookworm: resolved (fixed in 4.8.2+dfsg-1) bullseye: resolved (fixed in 4.8.2+dfsg-1) forky: resolved (fixed in 4.8.2+dfsg-1) sid: resolved (fixed in 4.8.2+dfsg-1) trixie: resolved (fixed in 4.8.2+dfsg-1)
debian
CVE-2012-3384P4MEDIUMCVSS 6.8fixed in wordpress 3.4.1+dfsg-1 (bookworm)2012
CVE-2012-3384 [MEDIUM] CVE-2012-3384: wordpress - Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress b... Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Scope: local bookworm: resolved (fixed in 3.4.1+dfsg-1) bullseye: resolved (fixed in 3.4.1+dfsg-1) forky: resolved (fixed in 3.4.1+dfsg-1) sid: resolved (fixed in 3.4.1+dfsg-1)
debian
CVE-2017-14720P4MEDIUMCVSS 6.1fixed in wordpress 4.8.2+dfsg-1 (bookworm)2017
CVE-2017-14720 [MEDIUM] CVE-2017-14720: wordpress - Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the tem... Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name. Scope: local bookworm: resolved (fixed in 4.8.2+dfsg-1) bullseye: resolved (fixed in 4.8.2+dfsg-1) forky: resolved (fixed in 4.8.2+dfsg-1) sid: resolved (fixed in 4.8.2+dfsg-1) trixie: resolved (fixed in 4.8.2+dfsg-1)
debian
CVE-2017-14721P4MEDIUMCVSS 6.1fixed in wordpress 4.8.2+dfsg-1 (bookworm)2017
CVE-2017-14721 [MEDIUM] CVE-2017-14721: wordpress - Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin edito... Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name. Scope: local bookworm: resolved (fixed in 4.8.2+dfsg-1) bullseye: resolved (fixed in 4.8.2+dfsg-1) forky: resolved (fixed in 4.8.2+dfsg-1) sid: resolved (fixed in 4.8.2+dfsg-1) trixie: resolved (fixed in 4.8.2+dfsg-1)
debian
CVE-2017-5490P4MEDIUMCVSS 6.1fixed in wordpress 4.7.1+dfsg-1 (bookworm)2017
CVE-2017-5490 [MEDIUM] CVE-2017-5490: wordpress - Cross-site scripting (XSS) vulnerability in the theme-name fallback functionalit... Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php. Scope: local bookworm: resolved (fixed in 4.7.1+dfsg-1) bul
debian
CVE-2017-9061P4MEDIUMCVSS 6.1fixed in wordpress 4.7.5+dfsg-1 (bookworm)2017
CVE-2017-9061 [MEDIUM] CVE-2017-9061: wordpress - In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists whe... In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename. Scope: local bookworm: resolved (fixed in 4.7.5+dfsg-1) bullseye: resolved (fixed in 4.7.5+dfsg-1) forky: resolved (fixed in 4.7.5+dfsg-1) sid: resolved (fixed in
debian
CVE-2019-16221P4MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16221 [MEDIUM] CVE-2019-16221: wordpress - WordPress before 5.2.3 allows reflected XSS in the dashboard. WordPress before 5.2.3 allows reflected XSS in the dashboard. Scope: local bookworm: resolved (fixed in 5.2.3+dfsg1-1) bullseye: resolved (fixed in 5.2.3+dfsg1-1) forky: resolved (fixed in 5.2.3+dfsg1-1) sid: resolved (fixed in 5.2.3+dfsg1-1) trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2015-3439P4MEDIUMCVSS 4.3fixed in wordpress 4.2+dfsg-1 (bookworm)2015
CVE-2015-3439 [MEDIUM] CVE-2015-3439: wordpress - Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupl... Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as a
debian
CVE-2019-16217P4MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16217 [MEDIUM] CVE-2019-16217: wordpress - WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attach... WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. Scope: local bookworm: resolved (fixed in 5.2.3+dfsg1-1) bullseye: resolved (fixed in 5.2.3+dfsg1-1) forky: resolved (fixed in 5.2.3+dfsg1-1) sid: resolved (fixed in 5.2.3+dfsg1-1) trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2019-16781P4MEDIUMCVSS 5.8fixed in wordpress 5.3.2+dfsg1-1 (bookworm)2019
CVE-2019-16781 [MEDIUM] CVE-2019-16781: wordpress - In WordPress before 5.3.1, authenticated users with lower privileges (like contr... In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS. Scope: local bookworm: resolved (fixed in 5.3.2+dfsg1-1) bullseye: resolved (fixed in 5.3.2+dfsg1-1) forky:
debian
Debian Wordpress vulnerabilities | cvebase