CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39866  CVE-2009-2431  Candidate  WordPress 2.7.1 places the username of a post"s author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.  Assigned (20090710)  None (candidate not yet proposed)    View
43266  CVE-2010-0682  Candidate  WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.  Assigned (20100222)  None (candidate not yet proposed)    View
51730  CVE-2011-3818  Candidate  WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51038  CVE-2011-3126  Candidate  WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.  Assigned (20110810)  None (candidate not yet proposed)    View
51039  CVE-2011-3127  Candidate  WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.  Assigned (20110810)  None (candidate not yet proposed)    View

Page 20795 of 20943, showing 5 records out of 104715 total, starting on record 103971, ending on 103975

Actions