cbcvebase.

Debian Wordpress vulnerabilities

333 known vulnerabilities affecting debian/wordpress.

Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57

Vulnerabilities

Page 6 of 17
CVE-2019-17675P3HIGHCVSS 8.8fixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17675 [HIGH] CVE-2019-17675: wordpress - WordPress before 5.2.4 does not properly consider type confusion during validati... WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. Scope: local bookworm: resolved (fixed in 5.2.4+dfsg1-1) bullseye: resolved (fixed in 5.2.4+dfsg1-1) forky: resolved (fixed in 5.2.4+dfsg1-1) sid: resolved (fixed in 5.2.4+dfsg1-1) trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2016-6635P3HIGHCVSS 8.8fixed in wordpress 4.5+dfsg-1 (bookworm)2016
CVE-2016-6635 [HIGH] CVE-2016-6635: wordpress - Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_te... Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option. Scope: local bookworm: resolved (fixed in 4.5+dfsg-1) bullseye: resolved (fixed in 4.5+
debian
CVE-2014-2053P3HIGHCVSS 7.5fixed in php-getid3 1.9.7-2 (bookworm)2014
CVE-2014-2053 [HIGH] CVE-2014-2053: php-getid3 - getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before... getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. Scope: local bookworm: resolved (fixed in 1.9.7-2) bullseye: resolved (fixed in 1.9.7-2) forky: resolved (fixed in 1.9.7-2) sid: res
debian
CVE-2020-28033P3HIGHCVSS 7.5fixed in wordpress 5.5.3+dfsg1-1 (bookworm)2020
CVE-2020-28033 [HIGH] CVE-2020-28033: wordpress - WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite netw... WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. Scope: local bookworm: resolved (fixed in 5.5.3+dfsg1-1) bullseye: resolved (fixed in 5.5.3+dfsg1-1) forky: resolved (fixed in 5.5.3+dfsg1-1) sid: resolved (fixed in 5.5.3+dfsg1-1) trixie: resolved (fixed in 5.5.3+dfsg1-1)
debian
CVE-2008-0193P4MEDIUMCVSS 4.3PoCfixed in wordpress 2.1.0-1 (bookworm)2008
CVE-2008-0193 [MEDIUM] CVE-2008-0193: wordpress - Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11... Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. Scope: local bookworm: resolved (fixed in 2.1.0-1) bullseye: resolved (fixed in 2.1.0-1) forky: res
debian
CVE-2007-3215P3HIGHCVSS 6.8fixed in libphp-phpmailer 1.73-4 (bookworm)2007
CVE-2007-3215 [MEDIUM] CVE-2007-3215: libphp-phpmailer - PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execu... PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php. Scope: local bookworm: resolved (fixed in 1.73-4) bullseye: resolved (fixed in 1.73-4) forky: resolved (fixed in 1.73-4) sid: resolved (fixed in 1.73-4) trixie: resolved (fi
debian
CVE-2014-0166P3MEDIUMCVSS 6.4fixed in wordpress 3.8.2+dfsg-1 (bookworm)2014
CVE-2014-0166 [MEDIUM] CVE-2014-0166: wordpress - The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress b... The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie. Scope: local bookworm: resolved (fixed in 3.8.2+dfsg-1) bullseye: resolved (fixed in 3.8.2+dfsg-1) for
debian
CVE-2008-6767P3LOWCVSS 10.0fixed in wordpress 2.8.3-1 (bookworm)2008
CVE-2008-6767 [CRITICAL] CVE-2008-6767: wordpress - wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to up... wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request. Scope: local bookworm: resolved (fixed in 2.8.3-1) bullseye: resolved (fixed in 2.8.3-1) forky: resolved (fixed in 2.8.3-1) sid: resolved (fixed in 2.8.3-1) trixie: resolved (fix
debian
CVE-2008-1930P3MEDIUMCVSS 9.8fixed in wordpress 2.5.1-1 (bookworm)2008
CVE-2008-1930 [CRITICAL] CVE-2008-1930: wordpress - The cookie authentication method in WordPress 2.5 relies on a hash of a concaten... The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptogra
debian
CVE-2007-4894P3MEDIUMCVSS 7.5fixed in wordpress 2.2.3-1 (bookworm)2007
CVE-2007-4894 [HIGH] CVE-2007-4894: wordpress - Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress m... Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query
debian
CVE-2004-1559P4MEDIUMCVSS 4.3PoCfixed in wordpress 1.2.2-1.1 (bookworm)2004
CVE-2004-1559 [MEDIUM] CVE-2004-1559: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remot... Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to
debian
CVE-2019-17673P3HIGHCVSS 7.5fixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17673 [HIGH] CVE-2019-17673: wordpress - WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET reque... WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. Scope: local bookworm: resolved (fixed in 5.2.4+dfsg1-1) bullseye: resolved (fixed in 5.2.4+dfsg1-1) forky: resolved (fixed in 5.2.4+dfsg1-1) sid: resolved (fixed in 5.2.4+dfsg1-1) trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2008-0192P4MEDIUMCVSS 4.3PoCfixed in wordpress 2.0.10-1 (bookworm)2008
CVE-2008-0192 [MEDIUM] CVE-2008-0192: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earli... Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php. Scope: local bookworm: resolved (fixed in 2.0.10-1) bullseye: resolved (fixed in 2.0.10-1) forky: resolved (fixed in 2.0.10-1) sid: resol
debian
CVE-2007-5105P4LOWCVSS 4.3PoCfixed in wordpress 2.0.4-1 (bookworm)2007
CVE-2007-5105 [MEDIUM] CVE-2007-5105: wordpress - Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and... Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter. Scope: local bookworm: resolved (fixed in 2.0.4-1) bullseye: resolved (fixed in 2.0.4-1) forky: resolved (fixed in 2.0.4-1) sid: resolved (fixed in 2.0.4-1) trixie: resolved (fixed in 2.
debian
CVE-2008-7220P3LOWCVSS 7.5fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2008
CVE-2008-7220 [HIGH] CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before... Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. Scope: local bullseye: resolved (fixed in 1:1.6.2.0~rc3-1) sid: resolved (fixed in 1:1.6.2.0~rc3-1)
debian
CVE-2016-7169P3MEDIUMCVSS 6.3fixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-7169 [MEDIUM] CVE-2016-7169: wordpress - Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/... Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter. Scope: local bookworm: resolved (fixed in 4.6.1+dfsg-1) bullseye: resolved (fixed in 4.6.1+df
debian
CVE-2017-14990P3MEDIUMCVSS 6.5fixed in wordpress 4.8.2+dfsg-2 (bookworm)2017
CVE-2017-14990 [MEDIUM] CVE-2017-14990: wordpress - WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores th... WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability). Scope: local bookworm: resolv
debian
CVE-2017-9064P3HIGHCVSS 8.8fixed in wordpress 4.7.5+dfsg-1 (bookworm)2017
CVE-2017-9064 [HIGH] CVE-2017-9064: wordpress - In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exi... In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials. Scope: local bookworm: resolved (fixed in 4.7.5+dfsg-1) bullseye: resolved (fixed in 4.7.5+dfsg-1) forky: resolved (fixed in 4.7.5+dfsg-1) sid: resolved (fixed in 4.7.5+dfsg-1) trixie: reso
debian
CVE-2017-5489P3HIGHCVSS 8.8fixed in wordpress 4.7.1+dfsg-1 (bookworm)2017
CVE-2017-5489 [HIGH] CVE-2017-5489: wordpress - Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows... Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload. Scope: local bookworm: resolved (fixed in 4.7.1+dfsg-1) bullseye: resolved (fixed in 4.7.1+dfsg-1) forky: resolved (fixed in 4.7.1+dfsg-1) sid: resolved (fixed in 4.7.1+dfsg-1
debian
CVE-2012-6707P3HIGHCVSS 7.5fixed in wordpress 6.8.1+dfsg1-1 (forky)2012
CVE-2012-6707 [HIGH] CVE-2012-6707: wordpress - WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which ... WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different
debian
Debian Wordpress vulnerabilities | cvebase