Debian Wordpress vulnerabilities
333 known vulnerabilities affecting debian/wordpress.
Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57
Vulnerabilities
Page 5 of 17
CVE-2004-1584P4MEDIUMCVSS 5.0PoCfixed in wordpress 1.2.1-1.1 (bookworm)2004
CVE-2004-1584 [MEDIUM] CVE-2004-1584: wordpress - CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote atta...
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
Scope: local
bookworm: resolved (fixed in 1.2.1-1.1)
bullseye: resolved (fixed in 1.2.1-1.1)
forky: resolved (fixed in 1.2.1-1.1)
sid: resolved (fixed in 1.2.1-1.1)
debian
CVE-2003-1598P3HIGHCVSS 7.5fixed in wordpress 1.0.1-1 (bookworm)2003
CVE-2003-1598 [HIGH] CVE-2003-1598: wordpress - SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allow...
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
Scope: local
bookworm: resolved (fixed in 1.0.1-1)
bullseye: resolved (fixed in 1.0.1-1)
forky: resolved (fixed in 1.0.1-1)
sid: resolved (fixed in 1.0.1-1)
trixie: resolved (fixed in 1.0.1-1)
debian
CVE-2013-4339P3HIGHCVSS 7.5fixed in wordpress 3.6.1+dfsg-1 (bookworm)2013
CVE-2013-4339 [HIGH] CVE-2013-4339: wordpress - WordPress before 3.6.1 does not properly validate URLs before use in an HTTP red...
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
Scope: local
bookworm: resolved (fixed in 3.6.1+dfsg-1)
bullseye: resolved (fixed in 3.6.1+dfsg-1)
forky: resolved (fixed in 3.6.1+dfsg-1)
sid: resolved (fixed in 3.6.1+dfsg-1)
trixie:
debian
CVE-2018-20151P3HIGHCVSS 7.5fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20151 [HIGH] CVE-2018-20151: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could b...
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
Scope: local
bookworm: resolved (fixed in 5.0.1+dfsg1-1)
bullseye: resolved (
debian
CVE-2009-2851P4LOWCVSS 4.3PoCfixed in wordpress 2.8.3-1 (bookworm)2009
CVE-2009-2851 [MEDIUM] CVE-2009-2851: wordpress - Cross-site scripting (XSS) vulnerability in the administrator interface in WordP...
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
Scope: local
bookworm: resolved (fixed in 2.8.3-1)
bullseye: resolved (fixed in 2.8.3-1)
forky: resolved (fixed in 2.8.3-1)
sid: resolved (fixed in 2.8.3-1)
trixie: resolved (fixe
debian
CVE-2014-5203P3HIGHCVSS 7.5fixed in wordpress 3.9.2+dfsg-1 (bookworm)2014
CVE-2014-5203 [HIGH] CVE-2014-5203: wordpress - wp-includes/class-wp-customize-widgets.php in the widget implementation in WordP...
wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.
Scope: local
bookworm: resolved (fixed in 3.9.2+dfsg-1)
bullseye: resolved (fixed in 3.9.2+dfsg-1)
forky: resolved (fixed in 3.9.2+dfsg-1)
sid: resolved (fixed in 3.9.2+dfsg-1)
tri
debian
CVE-2016-5839P3HIGHCVSS 7.5fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5839 [HIGH] CVE-2016-5839: wordpress - WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name ...
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.5.3+dfsg-1)
forky: resolved (fixed in 4.5.3+dfsg-1)
sid: resolved (fixed in 4.5.3+dfsg-1)
trixie: resolved (fixed in 4.5.3+dfsg-1)
debian
CVE-2007-6013P3LOWCVSS 9.8fixed in wordpress 2.5.0-1 (bookworm)2007
CVE-2007-6013 [CRITICAL] CVE-2007-6013: wordpress - Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a passwo...
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Scope: local
bookworm: resolved (fixed in 2.5.0-1)
bullseye: resolved (fixed in 2.5.0-1)
forky: resolved (fixed in
debian
CVE-2016-5832P3HIGHCVSS 7.5fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5832 [HIGH] CVE-2016-5832: wordpress - The customizer in WordPress before 4.5.3 allows remote attackers to bypass inten...
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.5.3+dfsg-1)
forky: resolved (fixed in 4.5.3+dfsg-1)
sid: resolved (fixed in 4.5.3+dfsg-1)
trixie: resolved (fixed in 4.5.3+dfsg-1)
debian
CVE-2016-5837P3HIGHCVSS 7.5fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5837 [HIGH] CVE-2016-5837: wordpress - WordPress before 4.5.3 allows remote attackers to bypass intended access restric...
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.5.3+dfsg-1)
forky: resolved (fixed in 4.5.3+dfsg-1)
sid: resolved (fixed in 4.5.3+dfsg-1)
trixie: resolved (fixed in 4.5.3+dfs
debian
CVE-2022-21663P3MEDIUMCVSS 6.6fixed in wordpress 5.8.3+dfsg1-1 (bookworm)2022
CVE-2022-21663 [MEDIUM] CVE-2022-21663: wordpress - WordPress is a free and open-source content management system written in PHP and...
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that
debian
CVE-2007-0540P4LOWCVSS 5.0PoCfixed in wordpress 2.1.0-1 (bookworm)2007
CVE-2007-0540 [MEDIUM] CVE-2007-0540: wordpress - WordPress allows remote attackers to cause a denial of service (bandwidth or thr...
WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.
Scope: local
bookworm: resolved (fixed in 2.1.0-1)
bullseye: resolved (fixed in 2.1.0-1)
forky: r
debian
CVE-2017-9062P3HIGHCVSS 8.6fixed in wordpress 4.7.5+dfsg-1 (bookworm)2017
CVE-2017-9062 [HIGH] CVE-2017-9062: wordpress - In WordPress before 4.7.5, there is improper handling of post meta data values i...
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
Scope: local
bookworm: resolved (fixed in 4.7.5+dfsg-1)
bullseye: resolved (fixed in 4.7.5+dfsg-1)
forky: resolved (fixed in 4.7.5+dfsg-1)
sid: resolved (fixed in 4.7.5+dfsg-1)
trixie: resolved (fixed in 4.7.5+dfsg-1)
debian
CVE-2020-11028P3MEDIUMCVSS 5.8fixed in wordpress 5.4.1+dfsg1-1 (bookworm)2020
CVE-2020-11028 [MEDIUM] CVE-2020-11028: wordpress - In affected versions of WordPress, some private posts, which were previously pub...
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4
debian
CVE-2017-5492P3HIGHCVSS 8.8fixed in wordpress 4.7.1+dfsg-1 (bookworm)2017
CVE-2017-5492 [HIGH] CVE-2017-5492: wordpress - Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibil...
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.
Scope: local
bookworm: resolved (fixed in 4
debian
CVE-2017-9065P3HIGHCVSS 7.5fixed in wordpress 4.7.5+dfsg-1 (bookworm)2017
CVE-2017-9065 [HIGH] CVE-2017-9065: wordpress - In WordPress before 4.7.5, there is a lack of capability checks for post meta da...
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
Scope: local
bookworm: resolved (fixed in 4.7.5+dfsg-1)
bullseye: resolved (fixed in 4.7.5+dfsg-1)
forky: resolved (fixed in 4.7.5+dfsg-1)
sid: resolved (fixed in 4.7.5+dfsg-1)
trixie: resolved (fixed in 4.7.5+dfsg-1)
debian
CVE-2016-5835P3HIGHCVSS 7.5fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5835 [HIGH] CVE-2016-5835: wordpress - WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-hist...
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.5.3+dfsg-1)
forky: resolved (fixed in 4.5.3+dfsg-1)
sid: resolved (fix
debian
CVE-2007-1049P4LOWCVSS 4.3PoCfixed in wordpress 2.1.1-1 (bookworm)2007
CVE-2007-1049 [MEDIUM] CVE-2007-1049: wordpress - Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the...
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.
Scope: loc
debian
CVE-2017-5493P3HIGHCVSS 7.5fixed in wordpress 4.7.1+dfsg-1 (bookworm)2017
CVE-2017-5493 [HIGH] CVE-2017-5493: wordpress - wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before ...
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
Scope: local
bookworm: resolved (fixed in 4.7.1+dfsg-1)
bullseye: resolved (fixed in 4.7.1+dfsg-1)
f
debian
CVE-2017-9066P3HIGHCVSS 8.6fixed in wordpress 4.7.5+dfsg-1 (bookworm)2017
CVE-2017-9066 [HIGH] CVE-2017-9066: wordpress - In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP...
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
Scope: local
bookworm: resolved (fixed in 4.7.5+dfsg-1)
bullseye: resolved (fixed in 4.7.5+dfsg-1)
forky: resolved (fixed in 4.7.5+dfsg-1)
sid: resolved (fixed in 4.7.5+dfsg-1)
trixie: resolved (fixed in 4.7.5+dfsg-1)
debian