Debian Wordpress vulnerabilities
333 known vulnerabilities affecting debian/wordpress.
Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57
Vulnerabilities
Page 7 of 17
CVE-2007-5710P4LOWCVSS 2.6PoCfixed in wordpress 2.3.1-1 (bookworm)2007
CVE-2007-5710 [LOW] CVE-2007-5710: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordP...
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.
Scope: local
bookworm: resolved (fixed in 2.3.1-1)
bullseye: resolved (fixed in 2.3.1-1)
forky: resolved (fixed in 2.3.1-1)
sid: resolved (fixed in 2.3.1-1)
trixie: resolved (fix
debian
CVE-2008-2146P3HIGHCVSS 7.5fixed in wordpress 2.2.3-1 (bookworm)2008
CVE-2008-2146 [HIGH] CVE-2008-2146: wordpress - wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the cur...
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye: resolved (fixed in 2.2.3-1)
forky: resolved (fixed in 2.2.3-1)
sid: resolved (fixed in 2.2.3-1)
t
debian
CVE-2008-3747P3LOWCVSS 7.5fixed in wordpress 2.5.1-6 (bookworm)2008
CVE-2008-3747 [HIGH] CVE-2008-3747: wordpress - The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-include...
The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.
Scope: local
bookworm: resolved (fixed in 2.5.1-6)
bullseye: resolved (fixed in
debian
CVE-2008-0194P3MEDIUMCVSS 6.0fixed in wordpress 2.1.0-1 (bookworm)2008
CVE-2008-0194 [MEDIUM] CVE-2008-0194: wordpress - Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and ear...
Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.
Scope: local
bookworm: resolved (fi
debian
CVE-2016-5836P3HIGHCVSS 7.5fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5836 [HIGH] CVE-2016-5836: wordpress - The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attac...
The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.5.3+dfsg-1)
forky: resolved (fixed in 4.5.3+dfsg-1)
sid: resolved (fixed in 4.5.3+dfsg-1)
trixie: resolved (fixed in 4.5.3+dfsg-1)
debian
CVE-2006-1012P3HIGHCVSS 7.5fixed in wordpress 2.0.1-1 (bookworm)2006
CVE-2006-1012 [HIGH] CVE-2006-1012: wordpress - SQL injection vulnerability in WordPress 1.5.2, and possibly other versions befo...
SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.
Scope: local
bookworm: resolved (fixed in 2.0.1-1)
bullseye: resolved (fixed in 2.0.1-1)
forky: resolved (fixed in 2.0.1-1)
sid: resolved (fixed in 2.0.1-1)
trixie:
debian
CVE-2018-20152P3MEDIUMCVSS 6.5fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20152 [MEDIUM] CVE-2018-20152: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended re...
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.
Scope: local
bookworm: resolved (fixed in 5.0.1+dfsg1-1)
bullseye: resolved (fixed in 5.0.1+dfsg1-1)
forky: resolved (fixed in 5.0.1+dfsg1-1)
sid: resolved (fixed in 5.0.1+dfsg1-1)
trixie: resolved (fixed in 5.0.1+dfsg1-1)
debian
CVE-2011-3129P3CRITICALCVSS 9.3fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-3129 [CRITICAL] CVE-2011-3129: wordpress - The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta ...
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (fixed in 3.2.1+dfsg-1)
forky: resolved (fixed in 3.2.1+dfsg-1)
sid:
debian
CVE-2010-4257P3MEDIUMCVSS 6.0fixed in wordpress 3.0.2-1 (bookworm)2010
CVE-2010-4257 [MEDIUM] CVE-2010-4257: wordpress - SQL injection vulnerability in the do_trackbacks function in wp-includes/comment...
SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved (fixed in 3.0.2-1)
forky: resolved (fixed in 3.0.2-1)
sid: resolved (fixed in 3.0.2-1)
debian
CVE-2005-1687P3HIGHCVSS 7.5fixed in wordpress 1.5.1-1 (bookworm)2005
CVE-2005-1687 [HIGH] CVE-2005-1687: wordpress - SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier all...
SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.
Scope: local
bookworm: resolved (fixed in 1.5.1-1)
bullseye: resolved (fixed in 1.5.1-1)
forky: resolved (fixed in 1.5.1-1)
sid: resolved (fixed in 1.5.1-1)
trixie: resolved (fixed in 1.5.1-1)
debian
CVE-2020-4047P3MEDIUMCVSS 6.8fixed in wordpress 5.4.2+dfsg1-1 (bookworm)2020
CVE-2020-4047 [MEDIUM] CVE-2020-4047: wordpress - In affected versions of WordPress, authenticated users with upload permissions (...
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previously affect
debian
CVE-2011-3130P3HIGHCVSS 7.5fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-3130 [HIGH] CVE-2011-3130: wordpress - wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has...
wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (fixed in 3.2.1+dfsg-1)
forky: resolved (fixed in 3.2.1+dfsg-1)
sid: resolved (fixed in 3.2.1+dfsg-1)
tri
debian
CVE-2018-20147P3MEDIUMCVSS 6.5fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20147 [MEDIUM] CVE-2018-20147: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to...
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.
Scope: local
bookworm: resolved (fixed in 5.0.1+dfsg1-1)
bullseye: resolved (fixed in 5.0.1+dfsg1-1)
forky: resolved (fixed in 5.0.1+dfsg1-1)
sid: resolved (fixed in 5.0.1+dfsg1-1)
trixie: resolved (fixed in 5.0.1+dfsg1-1)
debian
CVE-2017-5610P3MEDIUMCVSS 5.3fixed in wordpress 4.7.2+dfsg-1 (bookworm)2017
CVE-2017-5610 [MEDIUM] CVE-2017-5610: wordpress - wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7....
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
Scope: local
bookworm: resolved (fixed in 4.7.2+dfsg-1)
bullseye: resolved (fixed in 4.7.2+dfsg-1)
forky: resolved (fi
debian
CVE-2008-4106P3MEDIUMCVSS 5.1fixed in wordpress 2.5.1-8 (bookworm)2008
CVE-2008-4106 [MEDIUM] CVE-2008-4106: wordpress - WordPress before 2.6.2 does not properly handle MySQL warnings about insertion o...
WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then re
debian
CVE-2012-2400P4CRITICALCVSS 10.0fixed in wordpress 3.3.2+dfsg-1 (bookworm)2012
CVE-2012-2400 [CRITICAL] CVE-2012-2400: wordpress - Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3...
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
Scope: local
bookworm: resolved (fixed in 3.3.2+dfsg-1)
bullseye: resolved (fixed in 3.3.2+dfsg-1)
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+dfsg-1)
trixie: resolved (fixed in 3.3.2+dfsg-1)
debian
CVE-2011-1762P4MEDIUMCVSS 6.5fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-1762 [MEDIUM] CVE-2011-1762: wordpress - A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script impro...
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (fixed in 3.2.1+dfsg-1)
forky: resolved (fixed
debian
CVE-2005-1810P4HIGHCVSS 7.5fixed in wordpress 1.5.1.2-1 (bookworm)2005
CVE-2005-1810 [HIGH] CVE-2005-1810: wordpress - SQL injection vulnerability in template-functions-category.php in WordPress 1.5....
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.
Scope: local
bookworm: resolved (fixed in 1.5.1.2-1)
bullseye: resolved (fixed in 1.5.1.2-1)
forky: resolved (fixed in 1.5.1.2-1)
sid: resolved (fix
debian
CVE-2011-3122P4CRITICALCVSS 10.0fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-3122 [CRITICAL] CVE-2011-3122: wordpress - Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 ha...
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (fixed in 3.2.1+dfsg-1)
forky: resolved (fixed in 3.2.1+dfsg-1)
sid: resolved (fixed in 3.2.1+dfsg-1)
trixie: resolved (fixed in 3.2.1+dfsg-1)
debian
CVE-2011-3125P4CRITICALCVSS 10.0fixed in wordpress 3.2.1+dfsg-1 (bookworm)2011
CVE-2011-3125 [CRITICAL] CVE-2011-3125: wordpress - Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 ha...
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (fixed in 3.2.1+dfsg-1)
forky: resolved (fixed in 3.2.1+dfsg-1)
sid: resolved (fixed in 3.2.1+dfsg-1)
trixie: resolved (fixed in 3.2
debian