NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67818 | CVE-2005-2109 | wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
2079 | CVE-2008-2146 | wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages. | 2 | 7.5 | High | 2017-01-03 | 2008-11-15 | View | |
9822 | CVE-2011-3130 | wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection. | 2 | 7.5 | High | 2017-01-07 | 2012-06-28 | View | |
7125 | CVE-2017-5487 | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
32953 | CVE-2014-5204 | wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-25 | View |
Page 153 of 17672, showing 5 records out of 88360 total, starting on record 761, ending on 765