Known vulnerabilities in wordpress (Debian package) - page 3

Vendor: Debian
Software CPE: cpe:2.3:o:debian:wordpress_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 74
Public exploits: 12
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wordpress (Debian package) wordpress (Debian package) is affected by 74 known vulnerabilities: 1 critical, 9 high, 18 medium, 46 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU24143 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16780
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 08.01.2020 SB2019121301
SB2020010818
SB2020050617
#VU23945 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-20041
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 06.01.2020 SB2019121301
SB2020010818
SB2020050617
#VU23576 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16781
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 13.12.2019 SB2019121301
SB2020010818
SB2020050617
#VU23575 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-20042
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 13.12.2019 SB2019121301
SB2020010818
SB2020050617
#VU23574 - Improper Access Control
CVE-2019-20043
CWE-284 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 13.12.2019 SB2019121301
SB2020010818
SB2020050617
#VU21791 - Improper input validation
CVE-2019-17675
CWE-20 Medium
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 15.10.2019 SB2019101505
SB2020010818
SB2020050617
#VU21790 - Improper input validation
CVE-2019-17673
CWE-20 Medium
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 15.10.2019 SB2019101505
SB2020010818
SB2020050617
#VU21789 - Improper Access Control
CVE-2019-17671
CWE-284 Medium
Available
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 15.10.2019 SB2019101505
SB2020010818
SB2020050617
#VU21788 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-17672
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 15.10.2019 SB2019101505
SB2020010818
SB2020050617
#VU21787 - Server-Side Request Forgery (SSRF)
CVE-2019-17669
CWE-918 Medium
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 15.10.2019 SB2019101505
SB2020010818
SB2020050617
#VU21786 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-17674
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 15.10.2019 SB2019101505
SB2020010818
SB2020050617
#VU20887 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16222
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 05.09.2019 SB2019090504
SB2020010818
SB2020050617
#VU20886 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16221
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 05.09.2019 SB2019090504
SB2020010818
SB2020050617
#VU20885 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16219
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 05.09.2019 SB2019090504
SB2020010818
SB2020050617
#VU20883 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2019-16220
CWE-601 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 05.09.2019 SB2019090504
SB2020010818
SB2020050617
#VU20882 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16218
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1 05.09.2019 SB2019090504
SB2020010818
SB2020050617
#VU17803 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-8942
CWE-94 High
Available
No
4.7.5+dfsg-2+deb9u5 20.02.2019 SB2019022008
SB2019030103
#VU16529 - Exposure of sensitive information to an unauthorized actor
CVE-2018-20151
CWE-200 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16526 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20153
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16523 - Permissions, Privileges, and Access Controls
CVE-2018-20147
CWE-264 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103


Showing elements 41 - 60 out of 74