CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51042 | CVE-2011-3130 | Candidate | wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection. | Assigned (20110810) | None (candidate not yet proposed) | View | |
102307 | CVE-2017-5487 | Candidate | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | Assigned (20170114) | None (candidate not yet proposed) | View | |
72501 | CVE-2014-5204 | Candidate | wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack. | Assigned (20140813) | None (candidate not yet proposed) | View | |
72502 | CVE-2014-5205 | Candidate | wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack. | Assigned (20140813) | None (candidate not yet proposed) | View | |
102313 | CVE-2017-5493 | Candidate | wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup. | Assigned (20170114) | None (candidate not yet proposed) | View |
Page 134 of 20943, showing 5 records out of 104715 total, starting on record 666, ending on 670