Base locale WP Commander

Vulnérabilités WordPress connues

Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.

39 693 vulnérabilités indexées · 46 400 plages de versions · mise à jour le 03/09/2026 à 19:28

43 038 résultats

Page 3567 sur 3587

Vulnérabilité Critique · 9,8
Sermon Browser

Sermon Browser < 0.43.6 – SQL Injection

The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions before 0.43.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

[*, 0.43.6)

Correctif

0.43.6

Publication

26/04/2011

Vulnérabilité Moyenne · 6,1
Sermon Browser

Sermon Browser < 0.43.6 – Cross-Site Scripting

The Sermon Browser plugin for WordPress is vulnerable to Cross-Site Scripting via the 'file_name' parameter in versions before 0.43.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…

Versions affectées

[*, 0.43.6)

Correctif

0.43.6

Publication

26/04/2011

Vulnérabilité Moyenne · 6,1
SocialGrid

SocialGrid <= 2.4 – Cross-Site Scripting

The SocialGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘default_services’ parameter in versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.4

Correctif

Non indiqué

Publication

19/04/2011

CVE-2011-4957 Élevée · 7,5
WordPress

WordPress Core < 3.1.1 – Denial of Service

The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted…

Versions affectées

[*, 3.1.1)

Correctif

3.1.1

Publication

05/04/2011

Les résultats proviennent de la base de vulnérabilités synchronisée sur ce site. Une absence de résultat ne garantit pas qu’un composant est exempt de faille.