CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92657  CVE-2016-5837  Candidate  WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.  Assigned (20160623)  None (candidate not yet proposed)    View
90848  CVE-2016-4029  Candidate  WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.  Assigned (20160415)  None (candidate not yet proposed)    View
82900  CVE-2015-5623  Candidate  WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.  Assigned (20150723)  None (candidate not yet proposed)    View
76338  CVE-2014-9037  Candidate  WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.  Assigned (20141120)  None (candidate not yet proposed)    View
67574  CVE-2014-0165  Candidate  WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.  Assigned (20131203)  None (candidate not yet proposed)    View

Page 144 of 20943, showing 5 records out of 104715 total, starting on record 716, ending on 720

Actions