Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 16

Consultez 389 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 16 de l’annuaire.

389Vulnérabilités
17Critiques
387Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2008-5278 Élevée · 7,2
WordPress

WordPress Core < 2.6.5 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

Versions affectées

*-2.6.4

Correctif

2.6.5

Publication

25/12/2008

CVE-2008-6767 Moyenne · 5,3
WordPress

WordPress Core < 2.7 – Denial of Service

wp-admin/upgrade.php in WordPress up to and including 2.6.1, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request if WordPress is not yet setup by creating an empty…

Versions affectées

*-2.6.1

Correctif

2.7

Publication

22/12/2008

CVE-2008-4107 Moyenne · 6,5
WordPress

WordPress Core < 2.6.2 – Cryptographic Weakness

The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset…

Versions affectées

*-2.6.1

Correctif

2.6.2

Publication

08/09/2008

CVE-2008-3747 Moyenne · 5,9
WordPress

WordPress Core < 2.6.1 – Cryptographic Weakness

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

Versions affectées

*-2.6

Correctif

2.6.1

Publication

15/08/2008

CVE-2008-4769 Élevée · 7,5
WordPress

WordPress Core <= 2.3.3 – Directory Traversal

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details…

Versions affectées

*-2.3.3, 2.5

Correctif

2.5.1

Publication

25/04/2008

CVE-2008-1930 Élevée · 8,1
WordPress

WordPress Core < 2.5.1 – Authentication Bypass

The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as…

Versions affectées

*-2.5

Correctif

2.5.1

Publication

25/04/2008

CVE-2008-1304 Moyenne · 6,4
WordPress

WordPress Core <= 2.3.2 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action…

Versions affectées

*-2.3.2

Correctif

2.3.3

Publication

05/02/2008

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités