Known vulnerabilities in wordpress - page 3

Software: wordpress
Software CPE: cpe:2.3:o:fedoraproject:wordpress:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 61
Public exploits: 11
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wordpress wordpress is affected by 61 known vulnerabilities: 10 high, 21 medium, 30 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU5508 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-5612
CWE-79 Low
Available
No
4.7.2-1.el5, 4.7.2-1.el6, 4.7.2-1.el7, 4.7.2-1.fc24, 4.7.2-1.fc25 30.01.2017 SB2017012702
SB2017012604
SB2017012715
and 4 more
#VU5509 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-5611
CWE-89 Medium
No
No
4.7.2-1.el5, 4.7.2-1.el6, 4.7.2-1.el7, 4.7.2-1.fc24, 4.7.2-1.fc25 30.01.2017 SB2017012702
SB2017012605
SB2017012715
and 4 more
#VU5510 - Improper Access Control
CVE-2017-5610
CWE-284 Low
No
No
4.7.2-1.el5, 4.7.2-1.el6, 4.7.2-1.el7, 4.7.2-1.fc24, 4.7.2-1.fc25 30.01.2017 SB2017012702
SB2017012606
SB2017012715
and 4 more
#VU446 - Resource exhaustion
CVE-2014-5265
CWE-400 Low
Available
No
3.9.2-3.el5, 3.9.2-3.el6 14.09.2016 SB2015092615
SB2014080706
SB2014080707
and 4 more
#VU369 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2016-7169
CWE-22 Medium
No
No
4.6.1-1.el5, 4.6.1-1.el6, 4.6.1-1.el7, 4.6.1-1.fc23, 4.6.1-1.fc24, 4.6.1-1.fc25 07.09.2016 SB2016090704
SB2016093003
SB2016090705
and 6 more
#VU368 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-7168
CWE-79 Low
No
No
4.6.1-1.el5, 4.6.1-1.el6, 4.6.1-1.el7, 4.6.1-1.fc23, 4.6.1-1.fc24, 4.6.1-1.fc25 07.09.2016 SB2016090704
SB2016093003
SB2016090706
and 6 more
#VU353 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2016-6896
CWE-352 Medium
Available
No
4.6.1-1.el5, 4.6.1-1.el6, 4.6.1-1.el7, 4.6.1-1.fc23, 4.6.1-1.fc24, 4.6-2.fc25 30.08.2016 SB2016081806
SB2016082001
SB2016090302
and 5 more
#VU40680 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-3439
CWE-79 Low
No
No
4.2.1-1.fc22, 4.2.2-1.el5, 4.2.2-1.el6, 4.2.2-1.el7, 4.2.2-1.fc21 05.08.2015 SB2015042307
SB2015042308
SB2015042309
and 2 more
#VU40681 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-3438
CWE-79 Low
No
No
4.2.1-1.fc22, 4.2.2-1.el5, 4.2.2-1.el6, 4.2.2-1.el7, 4.2.2-1.fc21 05.08.2015 SB2015080502
SB2015042307
SB2015042308
and 3 more
#VU40684 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-3440
CWE-79 Low
Available
No
4.2.1-1.fc22, 4.2.2-1.el5, 4.2.2-1.el6, 4.2.2-1.el7, 4.2.2-1.fc21 03.08.2015 SB2015080304
SB2015042307
SB2015042308
and 3 more
#VU41396 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2014-5240
CWE-79 Low
No
No
3.9.2-3.el5, 3.9.2-3.el6 18.08.2014 SB2014080710
SB2014080711
#VU41397 - Improper input validation
CVE-2014-5203
CWE-20 Medium
No
No
3.9.2-3.el5, 3.9.2-3.el6 18.08.2014 SB2014081801
SB2014080710
SB2014080711
#VU41398 - Cross-Site Request Forgery (CSRF)
CVE-2014-5204
CWE-352 Medium
No
No
3.9.2-3.el5, 3.9.2-3.el6 18.08.2014 SB2014080710
SB2014080711
#VU41399 - Cross-Site Request Forgery (CSRF)
CVE-2014-5205
CWE-352 Medium
No
No
3.9.2-3.el5, 3.9.2-3.el6 18.08.2014 SB2014081802
SB2014080710
SB2014080711
#VU41842 - Improper Authentication
CVE-2014-0166
CWE-287 Medium
No
No
3.8.3-1.el5, 3.8.3-1.el6 10.04.2014 SB2014041005
SB2014040902
SB2014040903
#VU41843 - Permissions, Privileges, and Access Controls
CVE-2014-0165
CWE-264 Low
No
No
3.8.3-1.el5, 3.8.3-1.el6 10.04.2014 SB2014041005
SB2014040902
SB2014040903
#VU44126 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2012-2399
CWE-79 Low
No
No
3.5-1.el5 22.04.2012 SB2012042202
SB2012121202
#VU44128 - Permissions, Privileges, and Access Controls
CVE-2012-2402
CWE-264 Low
No
No
3.5-1.el5 22.04.2012 SB2012042202
SB2012121202
#VU44129 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2012-2403
CWE-79 Low
No
No
3.5-1.el5 22.04.2012 SB2012042202
SB2012121202
#VU44130 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2012-2404
CWE-79 Low
No
No
3.5-1.el5 22.04.2012 SB2012042202
SB2012121202


Showing elements 41 - 60 out of 61