Known vulnerabilities in wordpress

Software: wordpress
Software CPE: cpe:2.3:o:fedoraproject:wordpress:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 61
Public exploits: 11
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wordpress wordpress is affected by 61 known vulnerabilities: 10 high, 21 medium, 30 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141728 - Unrestricted Upload of File with Dangerous Type
CVE-2026-65640
CWE-434 Medium
No
No
6.9.7-1.el9, 6.9.7-1.el10_2, 6.9.7-1.fc43, 6.9.7-1.fc44, 7.0.4-1.el10_3 12.08.2026 SB20260812207
SB2026081316
SB2026081317
and 3 more
#VU141175 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-64638
CWE-79 High
Available
No
6.9.6-1.el9, 6.9.6-1.el10_2, 6.9.6-1.fc43, 6.9.6-1.fc44, 6.9.7-1.el9, 6.9.7-1.el10_2, 6.9.7-1.fc43, 6.9.7-1.fc44, 7.0.3-1.el10_3, 7.0.4-1.el10_3 07.08.2026 SB2026080702
SB2026080714
SB2026080715
and 9 more
#VU93316 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-6306
CWE-22 Medium
No
No
6.5.5-1.el9, 6.5.5-1.fc39, 6.5.5-1.fc40 25.06.2024 SB20240625118
SB2024070335
SB2024070336
and 1 more
#VU93315 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-32111
CWE-79 Low
No
No
6.5.5-1.el9, 6.5.5-1.fc39, 6.5.5-1.fc40 25.06.2024 SB20240625118
SB2024070335
SB2024070336
and 1 more
#VU93314 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-6307
CWE-79 Medium
No
No
6.5.5-1.el9, 6.5.5-1.fc39, 6.5.5-1.fc40 25.06.2024 SB20240625118
SB2024070335
SB2024070336
and 1 more
#VU88433 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Medium
No
No
6.4.4-1.fc38, 6.5.2-1.el9, 6.5.2-1.fc39, 6.5.2-1.fc40 10.04.2024 SB2024041077
SB2024041078
SB2024041079
and 2 more
#VU85994 - Improper Control of Generation of Code ('Code Injection')
CWE-94 High
No
No
5.1.18-1.el7, 6.4.3-1.el9, 6.4.3-1.fc38, 6.4.3-1.fc39 01.02.2024 SB2024020115
SB2024020125
SB2024020126
and 2 more
#VU85992 - Unrestricted Upload of File with Dangerous Type
CVE-2024-31210
CWE-434 Low
No
No
5.1.18-1.el7, 6.4.3-1.el9, 6.4.3-1.fc38, 6.4.3-1.fc39 01.02.2024 SB2024020115
SB2024020125
SB2024020126
and 3 more
#VU82043 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
6.3.2-1.el9, 6.3.2-1.fc38, 6.3.2-1.fc39 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 1 more
#VU82041 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Medium
No
No
5.1.17-1.el7, 6.2.3-1.fc37, 6.3.2-1.el9, 6.3.2-1.fc38, 6.3.2-1.fc39 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 3 more
#VU82032 - Improper Control of Generation of Code ('Code Injection')
CWE-94 Medium
No
No
5.1.17-1.el7, 6.2.3-1.fc37, 6.3.2-1.el9, 6.3.2-1.fc38, 6.3.2-1.fc39 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 3 more
#VU82027 - Deserialization of Untrusted Data
CWE-502 High
No
No
6.3.2-1.el9, 6.3.2-1.fc38, 6.3.2-1.fc39 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 1 more
#VU82022 - Exposure of sensitive information to an unauthorized actor
CVE-2023-5561
CWE-200 Medium
Available
No
5.1.17-1.el7, 6.2.3-1.fc37, 6.3.2-1.el9, 6.3.2-1.fc38, 6.3.2-1.fc39 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 4 more
#VU82019 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-38000
CWE-79 Low
No
No
5.1.17-1.el7, 6.2.3-1.fc37, 6.3.2-1.el9, 6.3.2-1.fc38, 6.3.2-1.fc39 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 4 more
#VU82018 - Improper Access Control
CVE-2023-39999
CWE-284 Low
No
No
5.1.17-1.el7, 6.2.3-1.fc37, 6.3.2-1.el9, 6.3.2-1.fc38, 6.3.2-1.fc39 16.10.2023 SB2023101623
SB2023101631
SB2023101632
and 4 more
#VU59291 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-21664
CWE-89 High
No
No
5.1.12-1.el7, 5.8.3-1.fc34, 5.8.3-1.fc35 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59290 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-21661
CWE-89 High
Available
No
5.1.12-1.el7, 5.8.3-1.fc34, 5.8.3-1.fc35 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59289 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21663
CWE-94 Low
No
No
5.1.12-1.el7, 5.8.3-1.fc34, 5.8.3-1.fc35 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59288 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21662
CWE-79 Medium
No
No
5.1.12-1.el7, 5.8.3-1.fc34, 5.8.3-1.fc35 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU48200 - Deserialization of Untrusted Data
CVE-2020-28032
CWE-502 High
Available
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more


Showing elements 1 - 20 out of 61