NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67818  CVE-2005-2109  wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.    Medium  2017-01-03  2016-10-17  View
2079  CVE-2008-2146  wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.    7.5  High  2017-01-03  2008-11-15  View
9822  CVE-2011-3130  wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.    7.5  High  2017-01-07  2012-06-28  View
7125  CVE-2017-5487  wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.    Medium  2017-07-18  2017-07-17  View
32953  CVE-2014-5204  wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.    6.8  Medium  2017-01-19  2015-11-25  View

Page 153 of 17672, showing 5 records out of 88360 total, starting on record 761, ending on 765

Actions