Known vulnerabilities in wordpress (Debian package) - page 4

Vendor: Debian
Software CPE: cpe:2.3:o:debian:wordpress_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 74
Public exploits: 12
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wordpress (Debian package) wordpress (Debian package) is affected by 74 known vulnerabilities: 1 critical, 9 high, 18 medium, 46 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU16528 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20149
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16527 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20150
CWE-79 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16525 - Improper input validation
CVE-2018-20148
CWE-20 High
Available
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU16524 - Permissions, Privileges, and Access Controls
CVE-2018-20152
CWE-264 Low
No
No
4.7.5+dfsg-2+deb9u5 13.12.2018 SB2018121308
SB2019030103
#VU9456 - Improper Access Control
CVE-2017-17092
CWE-284 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112938
#VU9455 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-17094
CWE-79 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112937
#VU9454 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-17093
CWE-79 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112936
#VU9453 - Use of Insufficiently Random Values
CVE-2017-17091
CWE-330 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 29.11.2017 SB2017112913
SB2018011714
SB2017112935
#VU9018 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-16510
CWE-89 Medium
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 31.10.2017 SB2017103106
SB2018011714
SB2017103115
#VU6593 - Cross-Site Request Forgery (CSRF)
CVE-2017-9066
CWE-352 Low
No
No
4.1+dfsg-1+deb8u16, 4.7.5+dfsg-2+deb9u2 17.05.2017 SB2017051701
SB2017060214
SB2018011714
and 1 more
#VU5935 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-6817
CWE-79 Low
No
No
4.1+dfsg-1+deb8u13 10.03.2017 SB2017030611
SB2017031625
SB2017032307
and 1 more
#VU5934 - Improper input validation
CVE-2017-6816
CWE-20 Low
No
No
4.1+dfsg-1+deb8u13 10.03.2017 SB2017030611
SB2017031625
SB2017032307
and 1 more
#VU5933 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2017-6815
CWE-601 Low
No
No
4.1+dfsg-1+deb8u13 10.03.2017 SB2017030611
SB2017031625
SB2017032307
and 1 more
#VU5932 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-6814
CWE-79 Low
No
No
4.1+dfsg-1+deb8u13 10.03.2017 SB2017030611
SB2017031625
SB2017032307
and 1 more


Showing elements 61 - 80 out of 74