Debian Wordpress vulnerabilities
333 known vulnerabilities affecting debian/wordpress.
Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57
Vulnerabilities
Page 16 of 17
CVE-2012-6635P4MEDIUMCVSS 4.0fixed in wordpress 3.4+dfsg-1 (bookworm)2012
CVE-2012-6635 [MEDIUM] CVE-2012-6635: wordpress - wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does n...
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.
Scope: local
bookworm: resolved (fixed in 3.4+dfsg-1)
bullseye: resolved (fixed in 3.4+dfsg-1)
forky: resolved (fixed in 3.4+dfsg-1)
sid: resolved (fix
debian
CVE-2020-4050P4LOWCVSS 3.5fixed in wordpress 5.4.2+dfsg1-1 (bookworm)2020
CVE-2020-4050 [LOW] CVE-2020-4050: wordpress - In affected versions of WordPress, misuse of the `set-screen-option` filter's re...
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected versions via a m
debian
CVE-2009-2432P4LOWCVSS 5.0fixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2432 [MEDIUM] CVE-2009-2432: wordpress - WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensiti...
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
Scope: local
bookworm: resolved (fixed in 2.8.3-1)
bullseye: resolved (fixed in 2.8.3-1)
forky: resolved (fixed in 2.8.3-1)
sid: resolved (fixed in 2.8.3-1)
trixie: resolved
debian
CVE-2006-3389P4LOWCVSS 5.0fixed in wordpress 2.0.4-1 (bookworm)2006
CVE-2006-3389 [MEDIUM] CVE-2006-3389: wordpress - index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive informa...
index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.
Scope: local
bookworm: resolved (fixed
debian
CVE-2007-1894P4MEDIUMCVSS 4.3fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-1894 [MEDIUM] CVE-2007-1894: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in ...
Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.
Scope: local
bookworm: resolved (fixed in 2.1.3-1)
bullseye: resolved (fixed in 2.1.3-1)
forky: resolved (fixed in 2.1.3-1)
sid: resolved (fixed in
debian
CVE-2005-2107P4MEDIUMCVSS 4.3fixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2107 [MEDIUM] CVE-2005-2107: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5...
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.
Scope: local
bookworm: resolved (fixed in 1.5.1.3-1)
bullseye: resolved (fixed in 1.5.1.3-1)
forky: resolved (fixed in 1.5.1.3-1)
sid: resolved (fixed in 1.5.1.3-1)
tr
debian
CVE-2008-2068P4MEDIUMCVSS 4.3fixed in wordpress 2.5.1-1 (bookworm)2008
CVE-2008-2068 [MEDIUM] CVE-2008-2068: wordpress - Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attacker...
Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.5.1-1)
bullseye: resolved (fixed in 2.5.1-1)
forky: resolved (fixed in 2.5.1-1)
sid: resolved (fixed in 2.5.1-1)
trixie: resolved (fixed in 2.5.1-1)
debian
CVE-2007-3639P4MEDIUMCVSS 4.0fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-3639 [MEDIUM] CVE-2007-3639: wordpress - WordPress before 2.2.2 allows remote attackers to redirect visitors to other web...
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-inc
debian
CVE-2007-4893P4LOWCVSS 4.3fixed in wordpress 2.2.3-1 (bookworm)2007
CVE-2007-4893 [MEDIUM] CVE-2007-4893: wordpress - wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user ...
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye:
debian
CVE-2010-2230P4MEDIUMCVSS 4.0fixed in wordpress 3.0.4+dfsg-1 (bookworm)2010
CVE-2010-2230 [MEDIUM] CVE-2010-2230: wordpress - The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9....
The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.
Scope: local
bookworm: resolved (fixed in 3.0.4+dfsg-1)
bullseye: resolved (fixed in 3.0.4+dfsg-1)
forky: resolved (fixed in 3.0.
debian
CVE-2010-5294P4MEDIUMCVSS 4.3fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-5294 [MEDIUM] CVE-2010-5294: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_cr...
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved
debian
CVE-2011-5270P4MEDIUMCVSS 4.0fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-5270 [MEDIUM] CVE-2011-5270: wordpress - wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_p...
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (fixed in 3.2.1+dfsg-1)
forky: resolved (fixed in 3.2.1+dfsg-1)
sid: resolved (
debian
CVE-2013-4340P4LOWCVSS 3.5fixed in wordpress 3.6.1+dfsg-1 (bookworm)2013
CVE-2013-4340 [LOW] CVE-2013-4340: wordpress - wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated...
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
Scope: local
bookworm: resolved (fixed in 3.6.1+dfsg-1)
bullseye: resolved (fixed in 3.6.1+dfsg-1)
forky: resolved (fixed in 3.6.1+dfsg-1)
sid: resolved (fixed in 3.6.1+dfsg-
debian
CVE-2005-1688P4MEDIUMCVSS 5.3fixed in wordpress 1.5.1-1 (bookworm)2005
CVE-2005-1688 [MEDIUM] CVE-2005-1688: wordpress - Wordpress 1.5 and earlier allows remote attackers to obtain sensitive informatio...
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
Scope: local
bookworm: resolved (fixed in 1.5.1-1)
bullseye: resolved (fixed in 1.5.1-1)
forky: resolved (fixed in 1.5.1-1)
sid: resolved (fixed in
debian
CVE-2013-2203P4MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2203 [MEDIUM] CVE-2013-2203: wordpress - WordPress before 3.5.2, when the uploads directory forbids write access, allows ...
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
debian
CVE-2007-4483P4MEDIUMCVSS 4.3fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-4483 [MEDIUM] CVE-2007-4483: wordpress - Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1...
Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).
Scope: local
bookworm: resolved (fixed in 2.1.3-1)
bullseye: resolved (fixed in 2.1.3-1)
forky: resolved (fixed in 2.1.3-1)
sid: resolved (fixed in 2.1.3-1)
t
debian
CVE-2006-1263P4MEDIUMCVSS 4.3fixed in wordpress 2.0.2-1 (bookworm)2006
CVE-2006-1263 [MEDIUM] CVE-2006-1263: wordpress - Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress b...
Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Scope: local
bookworm: resolved (fixed in 2.0.2-1)
bullseye: resolved (fixed in 2.0.2-1)
forky: resolved (fixed in 2.0.2-1)
sid: resolved (fixed in 2.0.2-1)
trixie: resolved (fixed in
debian
CVE-2013-5739P4LOWCVSS 3.5fixed in wordpress 3.6.1+dfsg-1 (bookworm)2013
CVE-2013-5739 [LOW] CVE-2013-5739: wordpress - The default configuration of WordPress before 3.6.1 does not prevent uploads of ...
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.
Scope: local
bookworm: resolved (fixed in 3.6.1+dfsg-1)
bullseye: r
debian
CVE-2012-4422P4LOWCVSS 3.5fixed in wordpress 3.4.2+dfsg-1 (bookworm)2012
CVE-2012-4422 [LOW] CVE-2012-4422: wordpress - wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is en...
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
Scope: local
bookworm: resolved (fixed in 3.4
debian
CVE-2007-5106P4LOWCVSS 4.3fixed in wordpress 2.0.2-1 (bookworm)2007
CVE-2007-5106 [MEDIUM] CVE-2007-5106: wordpress - Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 all...
Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter.
Scope: local
bookworm: resolved (fixed in 2.0.2-1)
bullseye: resolved (fixed in 2.0.2-1)
forky: resolved (fixed in 2.0.2-1)
sid: resolved (fixed in 2.0.2-1)
trixie: resolved (fixed in 2.0.2-1)
debian