Debian Wordpress vulnerabilities

360 known vulnerabilities affecting debian/wordpress.

Total CVEs
360
CISA KEV
0
Public exploits
67
Exploited in wild
3
Severity breakdown
CRITICAL21HIGH56MEDIUM201LOW82

Vulnerabilities

Page 16 of 18
CVE-2007-0106MEDIUMCVSS 6.8fixed in wordpress 2.0.6-1 (bookworm)2007
CVE-2007-0106 [MEDIUM] CVE-2007-0106: wordpress - Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPr... Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request. Scope: local bookwo
debian
CVE-2007-3544MEDIUMCVSS 6.0fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-3544 [MEDIUM] CVE-2007-3544: wordpress - Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in Word... Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of
debian
CVE-2007-1893MEDIUMCVSS 4.9fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-1893 [MEDIUM] CVE-2007-1893: wordpress - xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote auth... xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post." Scope: local bookworm: resolved (fixed in 2.1.3-1) bullseye: resolved (fixed in 2.1.3-1) forky: resolved
debian
CVE-2007-4154MEDIUMCVSS 6.5fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-4154 [MEDIUM] CVE-2007-4154: wordpress - SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote auth... SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly oth
debian
CVE-2007-1244MEDIUMCVSS 6.8PoCfixed in wordpress 2.1.2-1 (bookworm)2007
CVE-2007-1244 [MEDIUM] CVE-2007-1244: wordpress - Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2... Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter. Scope: local
debian
CVE-2007-4894MEDIUMCVSS 7.5fixed in wordpress 2.2.3-1 (bookworm)2007
CVE-2007-4894 [HIGH] CVE-2007-4894: wordpress - Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress m... Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query
debian
CVE-2007-4483MEDIUMCVSS 4.3fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-4483 [MEDIUM] CVE-2007-4483: wordpress - Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1... Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). Scope: local bookworm: resolved (fixed in 2.1.3-1) bullseye: resolved (fixed in 2.1.3-1) forky: resolved (fixed in 2.1.3-1) sid: resolved (fixed in 2.1.3-1) t
debian
CVE-2007-1622MEDIUMCVSS 4.3fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-1622 [MEDIUM] CVE-2007-1622: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress befor... Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF. Scope: local bookworm: res
debian
CVE-2007-4153LOWCVSS 2.1fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-4153 [LOW] CVE-2007-4153: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow rem... Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the
debian
CVE-2007-5106LOWCVSS 4.3fixed in wordpress 2.0.2-1 (bookworm)2007
CVE-2007-5106 [MEDIUM] CVE-2007-5106: wordpress - Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 all... Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter. Scope: local bookworm: resolved (fixed in 2.0.2-1) bullseye: resolved (fixed in 2.0.2-1) forky: resolved (fixed in 2.0.2-1) sid: resolved (fixed in 2.0.2-1) trixie: resolved (fixed in 2.0.2-1)
debian
CVE-2007-1409LOWCVSS 5.02007
CVE-2007-1409 [MEDIUM] CVE-2007-1409: wordpress - WordPress allows remote attackers to obtain sensitive information via a direct r... WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2007-6318LOWCVSS 6.8PoCfixed in wordpress 2.3.2-1 (bookworm)2007
CVE-2007-6318 [MEDIUM] CVE-2007-6318: wordpress - SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earl... SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character. Scope: local bookworm: resolved (fixed in 2.3.2-1) bullseye: resolved (
debian
CVE-2007-0539LOWCVSS 7.8fixed in wordpress 2.1.0-1 (bookworm)2007
CVE-2007-0539 [HIGH] CVE-2007-0539: wordpress - The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to ... The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint. Scope: local bookworm: resolved (fixed in 2.1.0-1) bullseye: resolved (fixed in
debian
CVE-2007-2383LOWCVSS 5.0fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2007
CVE-2007-2383 [MEDIUM] CVE-2007-2383: asterisk - The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using Java... The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijack
debian
CVE-2007-1732LOWCVSS 3.5fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-1732 [LOW] CVE-2007-1732: wordpress - Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php i... Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stat
debian
CVE-2007-2627LOWCVSS 4.3fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-2627 [MEDIUM] CVE-2007-2627: wordpress - Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custo... Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622. Scope: local bookworm: resolved (fixed in 2.2.2-1) bullseye: resolved (fixed in 2.2.2-1) forky: reso
debian
CVE-2007-5710LOWCVSS 2.6PoCfixed in wordpress 2.3.1-1 (bookworm)2007
CVE-2007-5710 [LOW] CVE-2007-5710: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordP... Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter. Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1) sid: resolved (fixed in 2.3.1-1) trixie: resolved (fix
debian
CVE-2007-0540LOWCVSS 5.0PoCfixed in wordpress 2.1.0-1 (bookworm)2007
CVE-2007-0540 [MEDIUM] CVE-2007-0540: wordpress - WordPress allows remote attackers to cause a denial of service (bandwidth or thr... WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data. Scope: local bookworm: resolved (fixed in 2.1.0-1) bullseye: resolved (fixed in 2.1.0-1) forky: r
debian
CVE-2007-0233LOWCVSS 9.3PoCfixed in wordpress 2.1.0-1 (bookworm)2007
CVE-2007-0233 [CRITICAL] CVE-2007-0233: wordpress - wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variable... wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP
debian
CVE-2007-4165LOWCVSS 6.82007
CVE-2007-4165 [MEDIUM] CVE-2007-4165: wordpress - Cross-site scripting (XSS) vulnerability in index.php in the Blue Memories theme... Cross-site scripting (XSS) vulnerability in index.php in the Blue Memories theme 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757 and CVE-2007-4014. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Scope:
debian