cbcvebase.

Debian Wordpress vulnerabilities

333 known vulnerabilities affecting debian/wordpress.

Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57

Vulnerabilities

Page 15 of 17
CVE-2013-5738P4MEDIUMCVSS 4.3fixed in wordpress 3.6.1+dfsg-1 (bookworm)2013
CVE-2013-5738 [MEDIUM] CVE-2013-5738: wordpress - The get_allowed_mime_types function in wp-includes/functions.php in WordPress be... The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file. Scope: local bookworm: resolved (fixed in 3.6.1+dfsg-1) bullseye:
debian
CVE-2014-9035P4MEDIUMCVSS 4.3fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9035 [MEDIUM] CVE-2014-9035: wordpress - Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5... Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.0.1+dfsg-1) bullseye: resolved (fixed in 4.0.1+dfsg-1) forky: resolved (fixed in 4.0.1+dfsg
debian
CVE-2006-1796P4MEDIUMCVSS 6.8fixed in wordpress 2.0.1 (bookworm)2006
CVE-2006-1796 [MEDIUM] CVE-2006-1796: wordpress - Cross-site scripting (XSS) vulnerability in the paging links functionality in te... Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']). Scope: local bookworm: resolved (fixed in 2.0.1) bullseye: r
debian
CVE-2013-2201P4MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2201 [MEDIUM] CVE-2013-2201: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 al... Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes. Scope: local bookworm: resolved (fixed in
debian
CVE-2007-1230P4MEDIUMCVSS 4.3fixed in wordpress 2.1.2-1 (bookworm)2007
CVE-2007-1230 [MEDIUM] CVE-2007-1230: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php... Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049. Scope: local bookworm: resolved (fixed in 2.1.2-1) bullseye: resolved (fixed in 2.1.2-1) forky: r
debian
CVE-2005-4463P4LOWCVSS 5.0fixed in wordpress 1.5.2-1 (bookworm)2005
CVE-2005-4463 [MEDIUM] CVE-2005-4463: wordpress - WordPress before 1.5.2 allows remote attackers to obtain sensitive information v... WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or fai
debian
CVE-2006-4743P4LOWCVSS 5.0fixed in wordpress 2.0.5-0.1 (bookworm)2006
CVE-2006-4743 [MEDIUM] CVE-2006-4743: wordpress - WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive inform... WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/
debian
CVE-2010-4536P4MEDIUMCVSS 4.3fixed in wordpress 3.0.4+dfsg-1 (bookworm)2010
CVE-2010-4536 [MEDIUM] CVE-2010-4536: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPres... Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form. Scope: local bookworm: resolved (fixed in 3.0.
debian
CVE-2011-4956P4MEDIUMCVSS 4.3fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-4956 [MEDIUM] CVE-2011-4956: wordpress - Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote... Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 3.2.1+dfsg-1) bullseye: resolved (fixed in 3.2.1+dfsg-1) forky: resolved (fixed in 3.2.1+dfsg-1) sid: resolved (fixed in 3.2.1+dfsg-1) trixie: resolved (fixed in 3.2.1+d
debian
CVE-2013-0236P4MEDIUMCVSS 4.3fixed in wordpress 3.5.1+dfsg-1 (bookworm)2013
CVE-2013-0236 [MEDIUM] CVE-2013-0236: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 al... Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post. Scope: local bookworm: resolved (fixed in 3.5.1+dfsg-1) bullseye: resolved (fixed in 3.5.1+dfsg-1) forky: resolved (fixed in 3.5.1+dfsg-1) sid: resolve
debian
CVE-2014-9036P4MEDIUMCVSS 4.3fixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9036 [MEDIUM] CVE-2014-9036: wordpress - Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before... Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post. Scope: local bookworm: resolved (fixed in 4.0.1+dfsg-1) bullseye: resolved (fixed in 4.0.1+dfsg-1) forky:
debian
CVE-2010-5295P4MEDIUMCVSS 4.3fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-5295 [MEDIUM] CVE-2010-5295: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress be... Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action. Scope: local bookworm: resolved (fixed in 3.0.2-1) bullseye: resolved (fixed in 3.0.2-1) forky: resolved (fixed in 3.
debian
CVE-2012-6633P4MEDIUMCVSS 4.3fixed in wordpress 3.4+dfsg-1 (bookworm)2012
CVE-2012-6633 [MEDIUM] CVE-2012-6633: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in W... Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field. Scope: local bookworm: resolved (fixed in 3.4+dfsg-1) bullseye: resolved (fixed in 3.4+dfsg-1) forky: resolved (fixed in 3.4+dfsg-1) sid: resolved (fixed in 3.4+dfsg-1) trix
debian
CVE-2014-0165P4MEDIUMCVSS 4.0fixed in wordpress 3.8.2+dfsg-1 (bookworm)2014
CVE-2014-0165 [MEDIUM] CVE-2014-0165: wordpress - WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users ... WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php. Scope: local bookworm: resolved (fixed in 3.8.2+dfsg-1) bullseye: resolved (fixed in 3.8.2+dfsg-1) forky: resolved (fixed in 3.8.2+dfsg-1) sid
debian
CVE-2007-0109P4LOWCVSS 5.0fixed in wordpress 2.0.6-1 (bookworm)2007
CVE-2007-0109 [MEDIUM] CVE-2007-0109: wordpress - wp-login.php in WordPress 2.0.5 and earlier displays different error messages if... wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks. Scope: local bookworm: resolved (fixed in 2.0.6-1) bullseye: resolved (fixed in 2.0.6-1) forky: resolved (fixed in 2.0.6-1) sid: resolved (fixed in 2.0.6-1) trixie:
debian
CVE-2006-0985P4MEDIUMCVSS 4.3fixed in wordpress 2.0.2-1 (bookworm)2006
CVE-2006-0985 [MEDIUM] CVE-2006-0985: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functi... Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters. Scope: local bookworm: resolved (fixed in 2.0.2-1) bullseye: resolved (fixed in 2.0.2-1) forky: resolved (fixed in 2.0.2-1) si
debian
CVE-2012-2403P4MEDIUMCVSS 4.3fixed in wordpress 3.3.2+dfsg-1 (bookworm)2012
CVE-2012-2403 [MEDIUM] CVE-2012-2403: wordpress - wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickabl... wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. Scope: local bookworm: resolved (fixed in 3.3.2+dfsg-1) bullseye: resolved (fixed in 3.3.2+dfsg-1) forky: resolved (fixed in 3.3.2+dfsg-1) sid: r
debian
CVE-2012-2404P4MEDIUMCVSS 4.3fixed in wordpress 3.3.2+dfsg-1 (bookworm)2012
CVE-2012-2404 [MEDIUM] CVE-2012-2404: wordpress - wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which... wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. Scope: local bookworm: resolved (fixed in 3.3.2+dfsg-1) bullseye: resolved (fixed in 3.3.2+dfsg-1) forky: resolved (fixed in 3.3.2+dfsg-1) sid: resolved (fixed in 3.3.2+dfsg-1)
debian
CVE-2007-1893P4MEDIUMCVSS 4.9fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-1893 [MEDIUM] CVE-2007-1893: wordpress - xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote auth... xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post." Scope: local bookworm: resolved (fixed in 2.1.3-1) bullseye: resolved (fixed in 2.1.3-1) forky: resolved
debian
CVE-2020-28040P4MEDIUMCVSS 4.3fixed in wordpress 5.5.3+dfsg1-1 (bookworm)2020
CVE-2020-28040 [MEDIUM] CVE-2020-28040: wordpress - WordPress before 5.5.2 allows CSRF attacks that change a theme's background imag... WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. Scope: local bookworm: resolved (fixed in 5.5.3+dfsg1-1) bullseye: resolved (fixed in 5.5.3+dfsg1-1) forky: resolved (fixed in 5.5.3+dfsg1-1) sid: resolved (fixed in 5.5.3+dfsg1-1) trixie: resolved (fixed in 5.5.3+dfsg1-1)
debian
Debian Wordpress vulnerabilities | cvebase