NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
9819 | CVE-2011-3127 | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. | 2 | 5.8 | Medium | 2017-01-07 | 2012-06-28 | View | |
9818 | CVE-2011-3126 | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. | 2 | 5 | Medium | 2017-01-07 | 2012-06-28 | View | |
10390 | CVE-2011-3818 | WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-05-21 | View | |
12229 | CVE-2010-0682 | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. | 2 | 4 | Medium | 2017-01-18 | 2011-01-19 | View | |
49676 | CVE-2009-2431 | WordPress 2.7.1 places the username of a post"s author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source. | 2 | 5 | Medium | 2017-01-07 | 2009-07-13 | View |
Page 169 of 17672, showing 5 records out of 88360 total, starting on record 841, ending on 845