cbcvebase.

Debian Wordpress vulnerabilities

333 known vulnerabilities affecting debian/wordpress.

Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57

Vulnerabilities

Page 12 of 17
CVE-2017-6817P4MEDIUMCVSS 5.4fixed in wordpress 4.7.3+dfsg-1 (bookworm)2017
CVE-2017-6817 [MEDIUM] CVE-2017-6817: wordpress - In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-... In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds. Scope: local bookworm: resolved (fixed in 4.7.3+dfsg-1) bullseye: resolved (fixed in 4.7.3+dfsg-1) forky: resolved (fixed in 4.7.3+dfsg-1) sid: resolved (fixed in 4.7.3+dfsg-1) trixie: resolved (fixed in 4.7.3+dfsg-1)
debian
CVE-2025-58674P4MEDIUMCVSS 5.9fixed in wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm)2025
CVE-2025-58674 [MEDIUM] CVE-2025-58674: wordpress - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti... Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress:
debian
CVE-2011-3128P4MEDIUMCVSS 5.0fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-3128 [MEDIUM] CVE-2011-3128: wordpress - WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments a... WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php. Scope: local bookworm: resolved (fixed in 3.2.1+dfsg-1) bullseye: resolved (fixed in 3.2.1+dfsg-1) forky: resolved (fixed in 3.2.1+dfsg-1) sid: resolved (fixed in 3.2.1
debian
CVE-2015-3438P4MEDIUMCVSS 4.3fixed in wordpress 4.2+dfsg-1 (bookworm)2015
CVE-2015-3438 [MEDIUM] CVE-2015-3438: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, w... Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment. Scope: local bookworm: resolved (fixed
debian
CVE-2021-29450P4MEDIUMCVSS 6.5fixed in wordpress 5.7.1+dfsg1-1 (bookworm)2021
CVE-2021-29450 [MEDIUM] CVE-2021-29450: wordpress - Wordpress is an open source CMS. One of the blocks in the WordPress editor can b... Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to re
debian
CVE-2017-5612P4MEDIUMCVSS 6.1fixed in wordpress 4.7.2+dfsg-1 (bookworm)2017
CVE-2017-5612 [MEDIUM] CVE-2017-5612: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-lis... Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt. Scope: local bookworm: resolved (fixed in 4.7.2+dfsg-1) bullseye: resolved (fixed in 4.7.2+dfsg-1) forky: resolved (fixed in 4.7.2+dfsg-1)
debian
CVE-2016-1564P4MEDIUMCVSS 6.1fixed in wordpress 4.4.1+dfsg-1 (bookworm)2016
CVE-2016-1564 [MEDIUM] CVE-2016-1564: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-them... Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php. Scope: local bookworm: resolved (fixed in 4.4.1+dfsg-1) bullseye: resolved (fixed in 4.4.1+dfsg-1) forky: resolved (fi
debian
CVE-2019-16220P4MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16220 [MEDIUM] CVE-2019-16220: wordpress - In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_r... In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash. Scope: local bookworm: resolved (fixed in 5.2.3+dfsg1-1) bullseye: resolved (fixed in 5.2.3+dfsg1-1) forky: resolved (fixed in 5.2.3+dfsg1-1) sid: resolved
debian
CVE-2016-6634P4MEDIUMCVSS 6.1fixed in wordpress 4.5+dfsg-1 (bookworm)2016
CVE-2016-6634 [MEDIUM] CVE-2016-6634: wordpress - Cross-site scripting (XSS) vulnerability in the network settings page in WordPre... Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.5+dfsg-1) bullseye: resolved (fixed in 4.5+dfsg-1) forky: resolved (fixed in 4.5+dfsg-1) sid: resolved (fixed in 4.5+dfsg-1) trixie: resolve
debian
CVE-2015-7989P4MEDIUMCVSS 6.1fixed in wordpress 4.3.1+dfsg-1 (bookworm)2015
CVE-2015-7989 [MEDIUM] CVE-2015-7989: wordpress - Cross-site scripting (XSS) vulnerability in the user list table in WordPress bef... Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714. Scope: local bookworm: resolved (fixed in 4.3.1+dfsg-1) bullseye: resolved (fixed in 4.3.1+dfsg-1) forky: resolved (fixed in 4.
debian
CVE-2017-9063P4MEDIUMCVSS 6.1fixed in wordpress 4.7.5+dfsg-1 (bookworm)2017
CVE-2017-9063 [MEDIUM] CVE-2017-9063: wordpress - In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to... In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session. Scope: local bookworm: resolved (fixed in 4.7.5+dfsg-1) bullseye: resolved (fixed in 4.7.5+dfsg-1) forky: resolved (fixed in 4.7.5+dfsg-1) sid: resolved (fixed in 4.7.5+dfsg-1) trixie: resolved (fixed in 4.7.5+dfsg-1)
debian
CVE-2023-38000P4MEDIUMCVSS 6.5fixed in wordpress 6.1.6+dfsg1-0+deb12u1 (bookworm)2023
CVE-2023-38000 [MEDIUM] CVE-2023-38000: wordpress - Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPres... Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions. Scope: local bookworm: resolved (fixed in 6.1.6+dfsg1-0+deb12u1) bullseye: resolved forky: resolved (fixed in 6.3.2+dfsg1-
debian
CVE-2017-5488P4MEDIUMCVSS 6.1fixed in wordpress 4.7.1+dfsg-1 (bookworm)2017
CVE-2017-5488 [MEDIUM] CVE-2017-5488: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php ... Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin. Scope: local bookworm: resolved (fixed in 4.7.1+dfsg-1) bullseye: resolved (fixed in 4.7.1+dfsg-1) forky: resolved (fixed in 4.7.1+dfsg-1) sid: re
debian
CVE-2009-3622P4MEDIUMCVSS 4.3fixed in wordpress 2.8.5-1 (bookworm)2009
CVE-2009-3622 [MEDIUM] CVE-2009-3622: wordpress - Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8... Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP. Scope: local bookworm: r
debian
CVE-2012-2401P4MEDIUMCVSS 5.0fixed in wordpress 3.3.2+dfsg-1 (bookworm)2012
CVE-2012-2401 [MEDIUM] CVE-2012-2401: wordpress - Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3... Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content. Scope: local bookworm: resolved (fixed in 3.3.2+dfsg-1) bullseye: resolved (fixed in 3.3.2+dfsg
debian
CVE-2017-17093P4MEDIUMCVSS 5.4fixed in wordpress 4.9.1+dfsg-1 (bookworm)2017
CVE-2017-17093 [MEDIUM] CVE-2017-17093: wordpress - wp-includes/general-template.php in WordPress before 4.9.1 does not properly res... wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site. Scope: local bookworm: resolved (fixed in 4.9.1+dfsg-1) bullseye: resolved (fixed in 4.9.1+dfsg-1) forky: resolved (fixed in 4.9.1+dfsg-1) sid: resolved
debian
CVE-2011-3126P4MEDIUMCVSS 5.0fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-3126 [MEDIUM] CVE-2011-3126: wordpress - WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to dete... WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. Scope: local bookworm: resolved (fixed in 3.2.1+dfsg-1) bullseye: resolved (fixed in 3.2.1+dfsg-1) forky: resolved (fixed in 3.2.1+dfsg-1) sid: resolved (fixed in 3.2.1+dfsg-1) trixie: resolved (fixed in 3.2.1+dfsg-1)
debian
CVE-2010-5296P4MEDIUMCVSS 4.9fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-5296 [MEDIUM] CVE-2010-5296: wordpress - wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configu... wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. Scope: local bookworm: resolved (fixed in 3.0.2-1) bullseye: resolved (fixed in 3.0.2-1) f
debian
CVE-2013-2204P4MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2204 [MEDIUM] CVE-2013-2204: wordpress - moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in ... moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string a
debian
CVE-2019-20043P4MEDIUMCVSS 4.3fixed in wordpress 5.3.2+dfsg1-1 (bookworm)2019
CVE-2019-20043 [MEDIUM] CVE-2019-20043: wordpress - In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordP... In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3
debian
Debian Wordpress vulnerabilities | cvebase