Known vulnerabilities in wordpress - page 2

Software: wordpress
Software CPE: cpe:2.3:o:fedoraproject:wordpress:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 61
Public exploits: 11
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wordpress wordpress is affected by 61 known vulnerabilities: 10 high, 21 medium, 30 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU48201 - Permissions, Privileges, and Access Controls
CVE-2020-28033
CWE-264 Medium
No
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48202 - Improper Access Control
CVE-2020-28036
CWE-284 High
No
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48040 - Cross-Site Request Forgery (CSRF)
CVE-2020-28040
CWE-352 Medium
No
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48039 - Improper Access Control
CVE-2020-28039
CWE-284 Medium
No
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48038 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-28038
CWE-79 Low
Available
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48037 - Resource Management Errors
CVE-2020-28037
CWE-399 High
No
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48036 - Permissions, Privileges, and Access Controls
CVE-2020-28035
CWE-264 Medium
No
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48035 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-28034
CWE-79 Medium
No
No
5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU29008 - Permissions, Privileges, and Access Controls
CVE-2020-4050
CWE-264 Low
No
No
5.1.6-1.el6, 5.1.6-1.el7, 5.4.2-1.fc31, 5.4.2-1.fc32 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29007 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2020-4048
CWE-601 Low
No
No
5.1.6-1.el6, 5.1.6-1.el7, 5.4.2-1.fc31, 5.4.2-1.fc32 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29006 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-4049
CWE-79 Low
No
No
5.1.6-1.el6, 5.1.6-1.el7, 5.4.2-1.fc31, 5.4.2-1.fc32 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29005 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-4047
CWE-79 Low
No
No
5.1.6-1.el6, 5.1.6-1.el7, 5.4.2-1.fc31, 5.4.2-1.fc32 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29004 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-4046
CWE-79 Low
No
No
5.1.6-1.el6, 5.1.6-1.el7, 5.4.2-1.fc31, 5.4.2-1.fc32 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU27443 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11026
CWE-79 Low
No
No
5.1.5-1.el6, 5.1.5-1.el7 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU27442 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11029
CWE-79 Medium
No
No
5.1.5-1.el6, 5.1.5-1.el7 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU27441 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11030
CWE-79 Low
No
No
5.1.5-1.el6, 5.1.5-1.el7 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU27440 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11025
CWE-79 Low
No
No
5.1.5-1.el6, 5.1.5-1.el7 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU27439 - Improper Access Control
CVE-2020-11028
CWE-284 Low
No
No
5.1.5-1.el6, 5.1.5-1.el7 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU27438 - Weak password recovery mechanism
CVE-2020-11027
CWE-640 High
Available
No
5.1.5-1.el6, 5.1.5-1.el7 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more
#VU13497 - Improper Access Control
CVE-2018-12895
CWE-284 Low
Available
No
4.9.7-1.el6, 4.9.7-1.el7, 4.9.7-1.fc27, 4.9.7-1.fc28 27.06.2018 SB2018062705
SB2018071902
SB2018062713
and 4 more


Showing elements 21 - 40 out of 61