CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
92657 | CVE-2016-5837 | Candidate | WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors. | Assigned (20160623) | None (candidate not yet proposed) | View | |
90848 | CVE-2016-4029 | Candidate | WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address. | Assigned (20160415) | None (candidate not yet proposed) | View | |
82900 | CVE-2015-5623 | Candidate | WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php. | Assigned (20150723) | None (candidate not yet proposed) | View | |
76338 | CVE-2014-9037 | Candidate | WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash. | Assigned (20141120) | None (candidate not yet proposed) | View | |
67574 | CVE-2014-0165 | Candidate | WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php. | Assigned (20131203) | None (candidate not yet proposed) | View |
Page 144 of 20943, showing 5 records out of 104715 total, starting on record 716, ending on 720