CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76339 | CVE-2014-9038 | Candidate | wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource. | Assigned (20141120) | None (candidate not yet proposed) | View | |
64285 | CVE-2013-4338 | Candidate | wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations. | Assigned (20130612) | None (candidate not yet proposed) | View | |
55646 | CVE-2012-2403 | Candidate | wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | Assigned (20120421) | None (candidate not yet proposed) | View | |
47877 | CVE-2010-5293 | Candidate | wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match. | Assigned (20140120) | None (candidate not yet proposed) | View | |
72500 | CVE-2014-5203 | Candidate | wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data. | Assigned (20140813) | None (candidate not yet proposed) | View |
Page 135 of 20943, showing 5 records out of 104715 total, starting on record 671, ending on 675