Debian Wordpress vulnerabilities
333 known vulnerabilities affecting debian/wordpress.
Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57
Vulnerabilities
Page 13 of 17
CVE-2015-5732P4MEDIUMCVSS 4.3fixed in wordpress 4.2.4+dfsg-1 (bookworm)2015
CVE-2015-5732 [MEDIUM] CVE-2015-5732: wordpress - Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu...
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.
Scope: local
bookworm: resolved (fixed in 4.2.4+dfsg-1)
bullseye: resolved (fixed in 4.2.4+dfsg-1)
forky: resolved (fixed in 4.2
debian
CVE-2015-5734P4MEDIUMCVSS 4.3fixed in wordpress 4.2.4+dfsg-1 (bookworm)2015
CVE-2015-5734 [MEDIUM] CVE-2015-5734: wordpress - Cross-site scripting (XSS) vulnerability in the legacy theme preview implementat...
Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.
Scope: local
bookworm: resolved (fixed in 4.2.4+dfsg-1)
bullseye: resolved (fixed in 4.2.4+dfsg-1)
forky: resolved (fixed in 4.2.4+dfsg-1)
sid: re
debian
CVE-2006-6016P4MEDIUMCVSS 6.5fixed in wordpress 2.0.5-0.1 (bookworm)2006
CVE-2006-6016 [MEDIUM] CVE-2006-6016: wordpress - wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated use...
wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.
Scope: local
bookworm: resolved (fixed in 2.0.5-0.1)
bullseye: resolved (fixed in 2.0.5-0.1)
forky: resolved (fixed in 2.0.5-0.1)
sid: resolved (fixed in 2.0.5-0.1)
trixie: resolved (fixed in 2.0.5-0.1)
debian
CVE-2026-3906P4LOWCVSS 4.3fixed in wordpress 6.9.4+dfsg1-1 (forky)2026
CVE-2026-3906 [MEDIUM] CVE-2026-3906: wordpress - WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9....
WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticate
debian
CVE-2014-9031P4MEDIUMCVSS 4.3fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9031 [MEDIUM] CVE-2014-9031: wordpress - Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPres...
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.
Scope: local
bookworm: resolved (fixed in 4.0.1+dfsg-1)
bullseye: res
debian
CVE-2011-4957P4MEDIUMCVSS 5.0fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-4957 [MEDIUM] CVE-2011-4957: wordpress - The make_clickable function in wp-includes/formatting.php in WordPress before 3....
The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (
debian
CVE-2007-0541P4LOWCVSS 5.0fixed in wordpress 2.1.0-1 (bookworm)2007
CVE-2007-0541 [MEDIUM] CVE-2007-0541: wordpress - WordPress allows remote attackers to determine the existence of arbitrary files,...
WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog
debian
CVE-2012-3385P4MEDIUMCVSS 5.0fixed in wordpress 3.4.1+dfsg-1 (bookworm)2012
CVE-2012-3385 [MEDIUM] CVE-2012-3385: wordpress - WordPress before 3.4.1 does not properly restrict access to post contents such a...
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.
Scope: local
bookworm: resolved (fixed in 3.4.1+dfsg-1)
bullseye: resolved (fixed in 3.4.1+dfsg-1)
forky: resolved (fixed in 3.4.1+dfsg-1)
sid: resolved (fixed in
debian
CVE-2007-0106P4MEDIUMCVSS 6.8fixed in wordpress 2.0.6-1 (bookworm)2007
CVE-2007-0106 [MEDIUM] CVE-2007-0106: wordpress - Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPr...
Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request.
Scope: local
bookwo
debian
CVE-2013-2199P4MEDIUMCVSS 6.4fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2199 [MEDIUM] CVE-2013-2199: wordpress - The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requ...
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
debian
CVE-2015-5733P4MEDIUMCVSS 4.3fixed in wordpress 4.2.4+dfsg-1 (bookworm)2015
CVE-2015-5733 [MEDIUM] CVE-2015-5733: wordpress - Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfIt...
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.
Scope: local
bookworm: resolved (fixed in 4.2.4+dfsg-1)
bullseye: resolved (fixed in 4.2.4+dfsg-1)
forky: resolved (fixed i
debian
CVE-2006-2702P4MEDIUMCVSS 5.0fixed in wordpress 2.0.3-1 (bookworm)2006
CVE-2006-2702 [MEDIUM] CVE-2006-2702: wordpress - vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote at...
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
Scope: local
bookworm: resolved (fixed in 2.0.3-1)
bullseye: resolved (fixed in 2.0.3-1)
forky: resolved (fixed in 2.0.3-1)
sid: resolved (fixed in 2.0.3-1)
trix
debian
CVE-2008-1502P4MEDIUMCVSS 4.3fixed in wordpress 2.5.0-1 (bookworm)2008
CVE-2008-1502 [MEDIUM] CVE-2008-1502: wordpress - The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as u...
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.
Scope: local
bookworm: resolved (fixed in 2.5.0-1)
bullseye: resolve
debian
CVE-2016-9263P4MEDIUMCVSS 4.7fixed in wordpress 4.1+dfsg-1 (bookworm)2016
CVE-2016-9263 [MEDIUM] CVE-2016-9263: wordpress - WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is n...
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.
Scope: local
bookworm: resolved (fixed in 4.1+dfsg-1)
bullseye: resolved (fixed in 4.1+dfsg-1)
forky: r
debian
CVE-2014-9039P4MEDIUMCVSS 4.3fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9039 [MEDIUM] CVE-2014-9039: wordpress - wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, ...
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
Scope: local
bookworm: resolved (fixed in 4.0.1+dfsg-1)
bullseye: resolved (fixed in 4.0.1+dfsg-1)
forky: resolved (fixed in 4.0.1+dfsg
debian
CVE-2007-3238P4LOWCVSS 4.3fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-3238 [MEDIUM] CVE-2007-3238: wordpress - Cross-site scripting (XSS) vulnerability in functions.php in the default theme i...
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Admi
debian
CVE-2023-39999P4MEDIUMCVSS 4.3fixed in wordpress 6.1.6+dfsg1-0+deb12u1 (bookworm)2023
CVE-2023-39999 [MEDIUM] CVE-2023-39999: wordpress - Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3...
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18,
debian
CVE-2013-2200P4MEDIUMCVSS 4.0fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2200 [MEDIUM] CVE-2013-2200: wordpress - WordPress before 3.5.2 does not properly check the capabilities of roles, which ...
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
sid: resolved
debian
CVE-2025-58246P4MEDIUMCVSS 4.3fixed in wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm)2025
CVE-2025-58246 [MEDIUM] CVE-2025-58246: wordpress - Insertion of Sensitive Information Into Sent Data vulnerability in WordPress all...
Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from
debian
CVE-2006-0986P4LOWCVSS 5.3fixed in wordpress 2.0.2-1 (bookworm)2006
CVE-2006-0986 [MEDIUM] CVE-2006-0986: wordpress - WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive informat...
WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php,
debian