Known vulnerabilities in wordpress (Debian package) 4.7.1+dfsg-1 - page 2

Vendor: Debian
Version: 4.7.1+dfsg-1
Software CPE: cpe:2.3:o:debian:wordpress_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 39
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting wordpress (Debian package) version 4.7.1+dfsg-1 wordpress (Debian package) 4.7.1+dfsg-1 is affected by 39 vulnerabilities: 3 high, 7 medium, 29 low Critical High Medium Low

Vulnerabilities (39)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU27442 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11029
CWE-79 Medium
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU27441 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11030
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU27439 - Improper Access Control
CVE-2020-11028
CWE-284 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU21786 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-17674
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 15.10.2019 SB2019101505
SB2020010818
SB2020050617
#VU17981 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-9787
CWE-79 Medium
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 13.03.2019 SB2019031311
SB2020050617
#VU17803 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-8942
CWE-94 High
Public exploit available
No
4.7.5+dfsg-2+deb9u5 20.02.2019 SB2019022008
SB2019030103
#VU16529 - Exposure of sensitive information to an unauthorized actor
CVE-2018-20151
CWE-200 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16528 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20149
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16527 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20150
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16526 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20153
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16525 - Improper input validation
CVE-2018-20148
CWE-20 High
Public exploit available
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16524 - Permissions, Privileges, and Access Controls
CVE-2018-20152
CWE-264 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16523 - Permissions, Privileges, and Access Controls
CVE-2018-20147
CWE-264 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU9456 - Improper Access Control
CVE-2017-17092
CWE-284 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112938
#VU9455 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-17094
CWE-79 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112937
#VU9454 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-17093
CWE-79 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112936
#VU9453 - Use of Insufficiently Random Values
CVE-2017-17091
CWE-330 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112935
#VU9018 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-16510
CWE-89 Medium
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 31.10.2017 SB2017103106
SB2018011714
SB2017103115
#VU6593 - Cross-Site Request Forgery (CSRF)
CVE-2017-9066
CWE-352 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 17.05.2017 SB2017051701
SB2017060214
SB2018011714
and 1 more


Showing elements 21 - 40 out of 39