CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51042  CVE-2011-3130  Candidate  wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.  Assigned (20110810)  None (candidate not yet proposed)    View
102307  CVE-2017-5487  Candidate  wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.  Assigned (20170114)  None (candidate not yet proposed)    View
72501  CVE-2014-5204  Candidate  wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.  Assigned (20140813)  None (candidate not yet proposed)    View
72502  CVE-2014-5205  Candidate  wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.  Assigned (20140813)  None (candidate not yet proposed)    View
102313  CVE-2017-5493  Candidate  wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.  Assigned (20170114)  None (candidate not yet proposed)    View

Page 134 of 20943, showing 5 records out of 104715 total, starting on record 666, ending on 670

Actions