CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51039 | CVE-2011-3127 | Candidate | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. | Assigned (20110810) | None (candidate not yet proposed) | View | |
51038 | CVE-2011-3126 | Candidate | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. | Assigned (20110810) | None (candidate not yet proposed) | View | |
51730 | CVE-2011-3818 | Candidate | WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
43266 | CVE-2010-0682 | Candidate | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. | Assigned (20100222) | None (candidate not yet proposed) | View | |
39866 | CVE-2009-2431 | Candidate | WordPress 2.7.1 places the username of a post"s author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source. | Assigned (20090710) | None (candidate not yet proposed) | View |
Page 149 of 20943, showing 5 records out of 104715 total, starting on record 741, ending on 745