Known vulnerabilities in wordpress (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:wordpress_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 74
Public exploits: 12
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wordpress (Debian package) wordpress (Debian package) is affected by 74 known vulnerabilities: 1 critical, 9 high, 18 medium, 46 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141175 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-64638
CWE-79 High
Available
No
6.8.7+dfsg1-0+deb13u1 07.08.2026 SB2026080702
SB2026080714
SB2026080715
and 9 more
#VU139076 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-60137
CWE-89 Critical
Available
Exploited
6.8.6+dfsg1-0+deb13u1 22.07.2026 SB2026072222
SB2026072443
#VU116652 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-58674
CWE-79 Low
No
No
6.8.3+dfsg1-0+deb13u1 07.10.2025 SB2025100716
SB2025122343
#VU116650 - Improper Access Control
CVE-2025-58246
CWE-284 Medium
No
No
6.8.3+dfsg1-0+deb13u1 07.10.2025 SB2025100716
SB2025122343
#VU85992 - Unrestricted Upload of File with Dangerous Type
CVE-2024-31210
CWE-434 Low
No
No
5.7.11+dfsg1-0+deb11u1, 6.1.6+dfsg1-0+deb12u1 01.02.2024 SB2024020115
SB2024020125
SB2024020126
and 3 more
#VU82022 - Exposure of sensitive information to an unauthorized actor
CVE-2023-5561
CWE-200 Medium
Available
No
5.7.11+dfsg1-0+deb11u1, 6.1.6+dfsg1-0+deb12u1 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 4 more
#VU82019 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-38000
CWE-79 Low
No
No
5.7.11+dfsg1-0+deb11u1, 6.1.6+dfsg1-0+deb12u1 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 4 more
#VU82018 - Improper Access Control
CVE-2023-39999
CWE-284 Low
No
No
5.7.11+dfsg1-0+deb11u1, 6.1.6+dfsg1-0+deb12u1 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 4 more
#VU76271 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-2745
CWE-22 Medium
No
No
5.7.11+dfsg1-0+deb11u1, 6.1.6+dfsg1-0+deb12u1 18.05.2023 SB2023051804
SB2024050867
#VU59291 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-21664
CWE-89 High
No
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59290 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-21661
CWE-89 High
Available
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59289 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21663
CWE-94 Low
No
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59288 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21662
CWE-79 Medium
No
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU56462 - Exposure of sensitive information to an unauthorized actor
CVE-2021-39200
CWE-200 Medium
No
No
5.0.14+dfsg1-0+deb10u1, 5.7.3+dfsg1-0+deb11u1 13.09.2021 SB2021091307
SB2021101502
#VU56461 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-39201
CWE-79 Low
No
No
5.0.14+dfsg1-0+deb10u1, 5.7.3+dfsg1-0+deb11u1 13.09.2021 SB2021091306
SB2021101502
#VU52550 - Permissions, Privileges, and Access Controls
CVE-2021-29450
CWE-264 Low
No
No
5.0.12+dfsg1-0+deb10u1 25.04.2021 SB2021042553
SB2021042336
#VU52549 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-29447
CWE-611 Medium
Available
No
5.0.12+dfsg1-0+deb10u1 25.04.2021 SB2021042553
SB2021042336
#VU48202 - Improper Access Control
CVE-2020-28036
CWE-284 High
No
No
5.0.11+dfsg1-0+deb10u1 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48040 - Cross-Site Request Forgery (CSRF)
CVE-2020-28040
CWE-352 Medium
No
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48039 - Improper Access Control
CVE-2020-28039
CWE-284 Medium
No
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more


Showing elements 1 - 20 out of 74