Debian Wordpress vulnerabilities
360 known vulnerabilities affecting debian/wordpress.
Total CVEs
360
CISA KEV
0
Public exploits
67
Exploited in wild
3
Severity breakdown
CRITICAL21HIGH56MEDIUM201LOW82
Vulnerabilities
Page 18 of 18
CVE-2006-0733LOWCVSS 2.6PoC2006
CVE-2006-0733 [LOW] CVE-2006-0733: wordpress - Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attack...
Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not
debian
CVE-2006-0986LOWCVSS 5.3fixed in wordpress 2.0.2-1 (bookworm)2006
CVE-2006-0986 [MEDIUM] CVE-2006-0986: wordpress - WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive informat...
WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php,
debian
CVE-2006-4743LOWCVSS 5.0fixed in wordpress 2.0.5-0.1 (bookworm)2006
CVE-2006-4743 [MEDIUM] CVE-2006-4743: wordpress - WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive inform...
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/
debian
CVE-2006-4208LOWCVSS 5.0PoCfixed in wordpress 2.0.5-0.1 (bookworm)2006
CVE-2006-4208 [MEDIUM] CVE-2006-4208: wordpress - Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plu...
Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.
Scope: local
bookworm: resolved (fixed in 2.0.5-0.1)
bullseye: resolved (fixed in 2.0.5-0.1)
forky: resolve
debian
CVE-2006-3389LOWCVSS 5.0fixed in wordpress 2.0.4-1 (bookworm)2006
CVE-2006-3389 [MEDIUM] CVE-2006-3389: wordpress - index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive informa...
index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.
Scope: local
bookworm: resolved (fixed
debian
CVE-2006-3390LOWCVSS 5.0fixed in wordpress 2.0.4-1 (bookworm)2006
CVE-2006-3390 [MEDIUM] CVE-2006-3390: wordpress - WordPress 2.0.3 allows remote attackers to obtain the installation path via a di...
WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.
Scope: local
bookworm: resolved (fixed in 2.0.4-1)
bullseye: resolved (fixed in 2.0.4-1)
forky: resolved (fixed in 2.0.4-1)
sid: r
debian
CVE-2005-1687HIGHCVSS 7.5fixed in wordpress 1.5.1-1 (bookworm)2005
CVE-2005-1687 [HIGH] CVE-2005-1687: wordpress - SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier all...
SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.
Scope: local
bookworm: resolved (fixed in 1.5.1-1)
bullseye: resolved (fixed in 1.5.1-1)
forky: resolved (fixed in 1.5.1-1)
sid: resolved (fixed in 1.5.1-1)
trixie: resolved (fixed in 1.5.1-1)
debian
CVE-2005-2108HIGHCVSS 7.5PoCfixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2108 [HIGH] CVE-2005-2108: wordpress - SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier al...
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.
Scope: local
bookworm: resolved (fixed in 1.5.1.3-1)
bullseye: resolved (fixed in 1.5.1.3-1)
forky: resolved (fixed in 1.5.1.3-
debian
CVE-2005-1810HIGHCVSS 7.5fixed in wordpress 1.5.1.2-1 (bookworm)2005
CVE-2005-1810 [HIGH] CVE-2005-1810: wordpress - SQL injection vulnerability in template-functions-category.php in WordPress 1.5....
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.
Scope: local
bookworm: resolved (fixed in 1.5.1.2-1)
bullseye: resolved (fixed in 1.5.1.2-1)
forky: resolved (fixed in 1.5.1.2-1)
sid: resolved (fix
debian
CVE-2005-2612HIGHCVSS 7.5PoCfixed in wordpress 1.5.2-1 (bookworm)2005
CVE-2005-2612 [HIGH] CVE-2005-2612: wordpress - Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remo...
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
Scope: local
bookworm: resolved (fixed in 1.5.2-1)
bullseye: resolved (fixed in 1.5.2-1)
forky: resolved (fixed in 1.5.2-1)
sid: resolved (fixed in 1.5.2-1)
trixie: resolved (fixed in 1.5.2-1)
debian
CVE-2005-4600MEDIUMCVSS 6.4PoCfixed in wordpress 2.5.1-3 (bookworm)2005
CVE-2005-4600 [MEDIUM] CVE-2005-4600: wordpress - Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP...
Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.
Scope: local
bookworm: resolved (fixed in 2.5.1-3)
bullseye: resolved (fixed in 2.5.1-3)
forky: resolved (fixed in
debian
CVE-2005-2110MEDIUMCVSS 5.0fixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2110 [MEDIUM] CVE-2005-2110: wordpress - WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive inform...
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
Scope: local
bookworm: resolved
debian
CVE-2005-1688MEDIUMCVSS 5.3fixed in wordpress 1.5.1-1 (bookworm)2005
CVE-2005-1688 [MEDIUM] CVE-2005-1688: wordpress - Wordpress 1.5 and earlier allows remote attackers to obtain sensitive informatio...
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
Scope: local
bookworm: resolved (fixed in 1.5.1-1)
bullseye: resolved (fixed in 1.5.1-1)
forky: resolved (fixed in 1.5.1-1)
sid: resolved (fixed in
debian
CVE-2005-2109MEDIUMCVSS 5.0fixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2109 [MEDIUM] CVE-2005-2109: wordpress - wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change ...
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.
Scope: local
bookworm: resolved (fixed in 1.5.1.3-1)
bullseye: resolved (fixed in 1.5.1.3-1)
forky: resolved (fixed in 1.5.1.3-1)
sid: resolved (fixed in 1.5.1.3-1)
trixi
debian
CVE-2005-2107MEDIUMCVSS 4.3fixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2107 [MEDIUM] CVE-2005-2107: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5...
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.
Scope: local
bookworm: resolved (fixed in 1.5.1.3-1)
bullseye: resolved (fixed in 1.5.1.3-1)
forky: resolved (fixed in 1.5.1.3-1)
sid: resolved (fixed in 1.5.1.3-1)
tr
debian
CVE-2005-3330LOWCVSS 7.5PoC2005
CVE-2005-3330 [HIGH] CVE-2005-3330: wordpress - The _httpsrequest function in Snoopy 1.2, as used in products such as (1) Magpie...
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.
Scope: local
bookworm: resolved
bullseye: resolved
forky: re
debian
CVE-2005-4463LOWCVSS 5.0fixed in wordpress 1.5.2-1 (bookworm)2005
CVE-2005-4463 [MEDIUM] CVE-2005-4463: wordpress - WordPress before 1.5.2 allows remote attackers to obtain sensitive information v...
WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or fai
debian
CVE-2004-1559MEDIUMCVSS 4.3PoCfixed in wordpress 1.2.2-1.1 (bookworm)2004
CVE-2004-1559 [MEDIUM] CVE-2004-1559: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remot...
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to
debian
CVE-2004-1584MEDIUMCVSS 5.0PoCfixed in wordpress 1.2.1-1.1 (bookworm)2004
CVE-2004-1584 [MEDIUM] CVE-2004-1584: wordpress - CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote atta...
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
Scope: local
bookworm: resolved (fixed in 1.2.1-1.1)
bullseye: resolved (fixed in 1.2.1-1.1)
forky: resolved (fixed in 1.2.1-1.1)
sid: resolved (fixed in 1.2.1-1.1)
debian
CVE-2003-1598HIGHCVSS 7.5fixed in wordpress 1.0.1-1 (bookworm)2003
CVE-2003-1598 [HIGH] CVE-2003-1598: wordpress - SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allow...
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
Scope: local
bookworm: resolved (fixed in 1.0.1-1)
bullseye: resolved (fixed in 1.0.1-1)
forky: resolved (fixed in 1.0.1-1)
sid: resolved (fixed in 1.0.1-1)
trixie: resolved (fixed in 1.0.1-1)
debian
← Previous18 / 18