Debian Wordpress vulnerabilities
333 known vulnerabilities affecting debian/wordpress.
Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57
Vulnerabilities
Page 17 of 17
CVE-2011-0700P4LOWCVSS 3.5fixed in wordpress 3.0.5+dfsg-1 (bookworm)2011
CVE-2011-0700 [LOW] CVE-2011-0700: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 al...
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
Scope: local
bookworm: resolv
debian
CVE-2005-2110P4MEDIUMCVSS 5.0fixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2110 [MEDIUM] CVE-2005-2110: wordpress - WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive inform...
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
Scope: local
bookworm: resolved
debian
CVE-2008-6762P4LOWCVSS 4.3fixed in wordpress 2.8.3-1 (bookworm)2008
CVE-2008-6762 [MEDIUM] CVE-2008-6762: wordpress - Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x...
Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.
Scope: local
bookworm: resolved (fixed in 2.8.3-1)
bullseye: resolved (fixed in 2.8.3-1)
forky: resolved (fixed in 2.8.3-1)
sid: resolved (fixed in 2.8.3-1
debian
CVE-2009-3891P4LOWCVSS 3.5fixed in wordpress 2.8.6-1 (bookworm)2009
CVE-2009-3891 [LOW] CVE-2009-3891: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress...
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).
Scope: local
bookworm: resolved (fixed in 2.8.6-1)
bullseye: resolved (fixed in 2.8.6-1)
forky: resolved (fixed in 2.8.6-1)
sid: resolved (fixed in 2.8.
debian
CVE-2010-5297P4LOWCVSS 2.1fixed in wordpress 3.0.1-1 (bookworm)2010
CVE-2010-5297 [LOW] CVE-2010-5297: wordpress - WordPress before 3.0.1, when a Multisite installation is used, permanently retai...
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.
Scope: local
bookworm: resolved (fixed in 3.0.1-1)
bullse
debian
CVE-2008-5113P4MEDIUMCVSS 4.0fixed in wordpress 2.5.1-10 (bookworm)2008
CVE-2008-5113 [MEDIUM] CVE-2008-5113: wordpress - WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous sit...
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue
debian
CVE-2012-3383P4LOWCVSS 2.6fixed in wordpress 3.4.1+dfsg-1 (bookworm)2012
CVE-2012-3383 [LOW] CVE-2012-3383: wordpress - The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x bef...
The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and compo
debian
CVE-2012-0287P4LOWCVSS 2.6fixed in wordpress 3.3.1+dfsg-1 (bookworm)2012
CVE-2012-0287 [LOW] CVE-2012-0287: wordpress - Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3....
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
Scope: local
bookworm: resolved (fixed in 3.3.1+dfsg-1)
bulls
debian
CVE-2020-4049P4LOWCVSS 2.4fixed in wordpress 5.4.2+dfsg1-1 (bookworm)2020
CVE-2020-4049 [LOW] CVE-2020-4049: wordpress - In affected versions of WordPress, when uploading themes, the name of the theme ...
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release
debian
CVE-2014-5240P4LOWCVSS 2.1fixed in wordpress 3.9.2+dfsg-1 (bookworm)2014
CVE-2014-5240 [LOW] CVE-2014-5240: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPre...
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
Scope: local
bookworm: resolved (fixed in 3.9.2+dfsg-1)
bullseye: resolved (fixed in 3.9.2+dfsg-1)
fo
debian
CVE-2007-4153P4LOWCVSS 2.1fixed in wordpress 2.2.2-1 (bookworm)2007
CVE-2007-4153 [LOW] CVE-2007-4153: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow rem...
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the
debian
CVE-2007-1732P4LOWCVSS 3.5fixed in wordpress 2.1.3-1 (bookworm)2007
CVE-2007-1732 [LOW] CVE-2007-1732: wordpress - Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php i...
Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stat
debian
CVE-2006-6017MEDIUMCVSS 6.5fixed in wordpress 2.0.5-0.1 (bookworm)2006
CVE-2006-6017 [MEDIUM] CVE-2006-6017: wordpress - WordPress before 2.0.5 does not properly store a profile containing a string rep...
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Scope: local
book
debian
← Previous17 / 17