cbcvebase.

Debian Wordpress vulnerabilities

333 known vulnerabilities affecting debian/wordpress.

Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57

Vulnerabilities

Page 14 of 17
CVE-2006-3390P4LOWCVSS 5.0fixed in wordpress 2.0.4-1 (bookworm)2006
CVE-2006-3390 [MEDIUM] CVE-2006-3390: wordpress - WordPress 2.0.3 allows remote attackers to obtain the installation path via a di... WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables. Scope: local bookworm: resolved (fixed in 2.0.4-1) bullseye: resolved (fixed in 2.0.4-1) forky: resolved (fixed in 2.0.4-1) sid: r
debian
CVE-2005-2109P4MEDIUMCVSS 5.0fixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2109 [MEDIUM] CVE-2005-2109: wordpress - wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change ... wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use. Scope: local bookworm: resolved (fixed in 1.5.1.3-1) bullseye: resolved (fixed in 1.5.1.3-1) forky: resolved (fixed in 1.5.1.3-1) sid: resolved (fixed in 1.5.1.3-1) trixi
debian
CVE-2016-7168P4MEDIUMCVSS 4.8fixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-7168 [MEDIUM] CVE-2016-7168: wordpress - Cross-site scripting (XSS) vulnerability in the media_handle_upload function in ... Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename. Scope: local bookworm: resolved (fixed in 4.6.1+dfsg-1) bullseye: resolved (f
debian
CVE-2013-2173P4MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2173 [MEDIUM] CVE-2013-2173: wordpress - wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post ... wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie. Scope: local bookworm: resolved (fixed in 3.5.2+dfsg-1) bullseye: resolved (fixed in 3.5.2+dfsg-1) forky: resolved (fixed in 3.5.2+dfsg-1) sid: resolved (
debian
CVE-2007-2627P4LOWCVSS 4.3fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-2627 [MEDIUM] CVE-2007-2627: wordpress - Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custo... Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622. Scope: local bookworm: resolved (fixed in 2.2.2-1) bullseye: resolved (fixed in 2.2.2-1) forky: reso
debian
CVE-2016-10148P4MEDIUMCVSS 4.3fixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-10148 [MEDIUM] CVE-2016-10148: wordpress - The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in Word... The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896. Scope: local bookwor
debian
CVE-2007-1599P4LOWCVSS 6.5fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-1599 [MEDIUM] CVE-2007-1599: wordpress - wp-login.php in WordPress allows remote attackers to redirect authenticated user... wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter. Scope: local bookworm: resolved (fixed in 2.2.2-1) bullseye: resolved (fixed in 2.2.2-1) forky: resolved (fixed in 2.2.2-1) sid: resolved (fixed in 2.2.2-1) trixie: resolved (fixed in 2.2.2-
debian
CVE-2011-3127P4MEDIUMCVSS 5.8fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-3127 [MEDIUM] CVE-2011-3127: wordpress - WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for ... WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. Scope: local bookworm: resolved (fixed in 3.2.1+dfsg-1) bullseye: resolved (fixed in 3.2.1+dfsg-1) forky: resol
debian
CVE-2008-0195P4LOWCVSS 5.0fixed in wordpress 2.1.0-1 (bookworm)2008
CVE-2008-0195 [MEDIUM] CVE-2008-0195: wordpress - WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive informa... WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages. Scope: local bookworm: resolved (fixed in 2.1.0-1) bullseye: resolved (fixed in 2.1.0-1) forky: resolved (fixed in 2.1.0-1) sid: resolved (fixed in 2.
debian
CVE-2015-3429P4MEDIUMCVSS 4.3fixed in wordpress 4.2.2+dfsg-1 (bookworm)2015
CVE-2015-3429 [MEDIUM] CVE-2015-3429: wordpress - Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.... Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier. Scope: local bookworm: resolved (fixed in 4.2.2+dfsg-1) bullseye: resolved (fixed in 4.2.2+dfsg-1) forky: resolved (fixed in 4.2.2+dfsg-1) sid: resolved (fi
debian
CVE-2013-2205P4MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2205 [MEDIUM] CVE-2013-2205: wordpress - The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestri... The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site. Scope: local bookworm: resolved (fixed in 3.5.2+dfsg-1) bullseye: resolved (fixed in 3.5.2+dfsg-1) forky: resolved (
debian
CVE-2014-9032P4MEDIUMCVSS 4.3fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9032 [MEDIUM] CVE-2014-9032: wordpress - Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordP... Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.0.1+dfsg-1) bullseye: resolved (fixed in 4.0.1+dfsg-1) forky: resolved (fixed in 4.0.1+dfsg-1) sid: re
debian
CVE-2012-4421P4MEDIUMCVSS 4.0fixed in wordpress 3.4.2+dfsg-1 (bookworm)2012
CVE-2012-4421 [MEDIUM] CVE-2012-4421: wordpress - The create_post function in wp-includes/class-wp-atom-server.php in WordPress be... The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature. Scope: local bookworm: resolved (fixed i
debian
CVE-2007-1622P4MEDIUMCVSS 4.3fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-1622 [MEDIUM] CVE-2007-1622: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress befor... Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF. Scope: local bookworm: res
debian
CVE-2009-2431P4LOWCVSS 5.0fixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2431 [MEDIUM] CVE-2009-2431: wordpress - WordPress 2.7.1 places the username of a post's author in an HTML comment, which... WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source. Scope: local bookworm: resolved (fixed in 2.8.3-1) bullseye: resolved (fixed in 2.8.3-1) forky: resolved (fixed in 2.8.3-1) sid: resolved (fixed in 2.8.3-1) trixie: resolved (fixed in 2.8.3-1)
debian
CVE-2007-2383P4LOWCVSS 5.0fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2007
CVE-2007-2383 [MEDIUM] CVE-2007-2383: asterisk - The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using Java... The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijack
debian
CVE-2015-5622P4LOWCVSS 3.5fixed in wordpress 4.2.3+dfsg-1 (bookworm)2015
CVE-2015-5622 [LOW] CVE-2015-5622: wordpress - Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote... Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php. Scope: local bookworm: resolved (fixed in 4.2.3+dfsg-1) bullseye: r
debian
CVE-2008-5278P4LOWCVSS 4.3fixed in wordpress 2.5.1-11 (bookworm)2008
CVE-2008-5278 [MEDIUM] CVE-2008-5278: wordpress - Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS... Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable). Scope: local bookworm: resolved (fixed in 2.5.1-11) bullseye: resolved (fixed in 2.5.1-11) forky: resolved (fixed i
debian
CVE-2013-0237P4MEDIUMCVSS 4.3fixed in wordpress 3.5.1+dfsg-1 (bookworm)2013
CVE-2013-0237 [MEDIUM] CVE-2013-0237: wordpress - Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload be... Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. Scope: local bookworm: resolved (fixed in 3.5.1+dfsg-1) bullseye: resolved (fixed in 3.5.1+dfsg-1) forky: resolved (fixed in 3.5.1+dfsg
debian
CVE-2011-0701P4MEDIUMCVSS 4.0fixed in wordpress 3.0.5+dfsg-1 (bookworm)2011
CVE-2011-0701 [MEDIUM] CVE-2011-0701: wordpress - wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows... wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter. Scope: local bookworm: resolved (fixed in 3.0.5+dfsg-1) bullseye: resolved (fixed in 3.0.5+dfsg-1) forky: resolved (fixed in 3.0.5+dfsg-1) sid: resolved (fixed in 3.0.5+dfsg
debian
Debian Wordpress vulnerabilities | cvebase