Debian Wordpress vulnerabilities
360 known vulnerabilities affecting debian/wordpress.
Total CVEs
360
CISA KEV
0
Public exploits
67
Exploited in wild
3
Severity breakdown
CRITICAL21HIGH56MEDIUM201LOW82
Vulnerabilities
Page 13 of 18
CVE-2011-4899LOWCVSS 7.5PoC2011
CVE-2011-4899 [HIGH] CVE-2011-4899: wordpress - wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and e...
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP re
debian
CVE-2010-5294MEDIUMCVSS 4.3fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-5294 [MEDIUM] CVE-2010-5294: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_cr...
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved
debian
CVE-2010-4257MEDIUMCVSS 6.0fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-4257 [MEDIUM] CVE-2010-4257: wordpress - SQL injection vulnerability in the do_trackbacks function in wp-includes/comment...
SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved (fixed in 3.0.2-1)
forky: resolved (fixed in 3.0.2-1)
sid: resolved (fixed in 3.0.2-1)
debian
CVE-2010-4536MEDIUMCVSS 4.3fixed in wordpress 3.0.4+dfsg-1 (bookworm)2010
CVE-2010-4536 [MEDIUM] CVE-2010-4536: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPres...
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
Scope: local
bookworm: resolved (fixed in 3.0.
debian
CVE-2010-5295MEDIUMCVSS 4.3fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-5295 [MEDIUM] CVE-2010-5295: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress be...
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved (fixed in 3.0.2-1)
forky: resolved (fixed in 3.
debian
CVE-2010-5106MEDIUMCVSS 6.5fixed in wordpress 3.0.3-1 (bookworm)2010
CVE-2010-5106 [MEDIUM] CVE-2010-5106: wordpress - The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 ...
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.
Scope: local
bookworm: resolved (fixed in 3.0.3-1)
bullseye: resolved (fixed in 3.0.3-
debian
CVE-2010-5296MEDIUMCVSS 4.9fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-5296 [MEDIUM] CVE-2010-5296: wordpress - wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configu...
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved (fixed in 3.0.2-1)
f
debian
CVE-2010-5293MEDIUMCVSS 5.8fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-5293 [MEDIUM] CVE-2010-5293: wordpress - wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist tr...
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved (fixed in 3.0.2-1)
forky: resolv
debian
CVE-2010-2230MEDIUMCVSS 4.0fixed in wordpress 3.0.4+dfsg-1 (bookworm)2010
CVE-2010-2230 [MEDIUM] CVE-2010-2230: wordpress - The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9....
The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.
Scope: local
bookworm: resolved (fixed in 3.0.4+dfsg-1)
bullseye: resolved (fixed in 3.0.4+dfsg-1)
forky: resolved (fixed in 3.0.
debian
CVE-2010-0682LOWCVSS 4.0PoCfixed in wordpress 2.9.2-1 (bookworm)2010
CVE-2010-0682 [MEDIUM] CVE-2010-0682: wordpress - WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts...
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
Scope: local
bookworm: resolved (fixed in 2.9.2-1)
bullseye: resolved (fixed in 2.9.2-1)
forky: resolved (fixed in 2.9.2-1)
sid: resolved (fixed in 2.9.2-1)
trixie: resolved (fixed in 2.9.2-1)
debian
CVE-2010-1619LOWCVSS 4.32010
CVE-2010-1619 [MEDIUM] CVE-2010-1619: wordpress - Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities functi...
Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via crafted HTML entities.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolv
debian
CVE-2010-5297LOWCVSS 2.1fixed in wordpress 3.0.1-1 (bookworm)2010
CVE-2010-5297 [LOW] CVE-2010-5297: wordpress - WordPress before 3.0.1, when a Multisite installation is used, permanently retai...
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.
Scope: local
bookworm: resolved (fixed in 3.0.1-1)
bullse
debian
CVE-2009-2853CRITICALCVSS 10.0fixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2853 [CRITICAL] CVE-2009-2853: wordpress - Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct r...
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
Scope: local
bookworm: resolved (fixed in 2.8.3-
debian
CVE-2009-2854MEDIUMCVSS 6.4fixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2854 [MEDIUM] CVE-2009-2854: wordpress - Wordpress before 2.8.3 does not check capabilities for certain actions, which al...
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-a
debian
CVE-2009-3622MEDIUMCVSS 4.3fixed in wordpress 2.8.5-1 (bookworm)2009
CVE-2009-3622 [MEDIUM] CVE-2009-3622: wordpress - Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8...
Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.
Scope: local
bookworm: r
debian
CVE-2009-2762LOWCVSS 7.5PoCfixed in wordpress 2.8.3-2 (bookworm)2009
CVE-2009-2762 [HIGH] CVE-2009-2762: wordpress - wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a p...
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.
Scope: local
bookworm: resolved (fixed in 2.8.3-2)
bullseye: resolved (fixed in 2.8.3-2)
debian
CVE-2009-2431LOWCVSS 5.0fixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2431 [MEDIUM] CVE-2009-2431: wordpress - WordPress 2.7.1 places the username of a post's author in an HTML comment, which...
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
Scope: local
bookworm: resolved (fixed in 2.8.3-1)
bullseye: resolved (fixed in 2.8.3-1)
forky: resolved (fixed in 2.8.3-1)
sid: resolved (fixed in 2.8.3-1)
trixie: resolved (fixed in 2.8.3-1)
debian
CVE-2009-2335LOWCVSS 5.0PoCfixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2335 [MEDIUM] CVE-2009-2335: wordpress - WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed ...
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
Scope: local
bookworm: resolved (fixe
debian
CVE-2009-2336LOWCVSS 5.0PoCfixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2336 [MEDIUM] CVE-2009-2336: wordpress - The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits...
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
Scope: l
debian
CVE-2009-2851LOWCVSS 4.3PoCfixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2851 [MEDIUM] CVE-2009-2851: wordpress - Cross-site scripting (XSS) vulnerability in the administrator interface in WordP...
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
Scope: local
bookworm: resolved (fixed in 2.8.3-1)
bullseye: resolved (fixed in 2.8.3-1)
forky: resolved (fixed in 2.8.3-1)
sid: resolved (fixed in 2.8.3-1)
trixie: resolved (fixe
debian