CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23590  CVE-2007-0233  Candidate  wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter"s hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.  Assigned (20070112)  None (candidate not yet proposed)    View
40287  CVE-2009-2852  Candidate  WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function.  Assigned (20090818)  None (candidate not yet proposed)    View
60668  CVE-2013-0721  Candidate  wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.  Assigned (20130102)  None (candidate not yet proposed)    View
102311  CVE-2017-5491  Candidate  wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.  Assigned (20170114)  None (candidate not yet proposed)    View
76340  CVE-2014-9039  Candidate  wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.  Assigned (20141120)  None (candidate not yet proposed)    View

Page 132 of 20943, showing 5 records out of 104715 total, starting on record 656, ending on 660

Actions