Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 16

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 16 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2008-3747 Moyenne · 5,9
WordPress

WordPress Core < 2.6.1 – Cryptographic Weakness

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

Versions affectées

*-2.6

Correctif

2.6.1

Publication

15/08/2008

CVE-2008-4769 Élevée · 7,5
WordPress

WordPress Core <= 2.3.3 – Directory Traversal

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details…

Versions affectées

*-2.3.3, 2.5

Correctif

2.5.1

Publication

25/04/2008

CVE-2008-1930 Élevée · 8,1
WordPress

WordPress Core < 2.5.1 – Authentication Bypass

The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as…

Versions affectées

*-2.5

Correctif

2.5.1

Publication

25/04/2008

CVE-2008-1304 Moyenne · 6,4
WordPress

WordPress Core <= 2.3.2 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action…

Versions affectées

*-2.3.2

Correctif

2.3.3

Publication

05/02/2008

CVE-2007-4894 Critique · 9,8
WordPress

WordPress Core < 2.2.3 & WordPress MU < 1.2.5a – SQL Injection

Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters…

Versions affectées

[*, 2.2.3)

Correctif

2.2.3

Publication

08/09/2007

CVE-2007-4894 Critique · 9,8
WordPress MU

WordPress Core < 2.2.3 & WordPress MU < 1.2.5a – SQL Injection

Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters…

Versions affectées

[*, 1.2.5)

Correctif

1.2.5

Publication

08/09/2007

CVE-2007-6318 Critique · 9,8
WordPress

WordPress Core < 2.3.2 – SQL Injection

SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that…

Versions affectées

*-2.3.1

Correctif

2.3.2

Publication

08/09/2007

CVE-2007-3639 Moyenne · 6,1
WordPress

WordPress Core < 2.2.2 – Open Redirect

WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2)…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

08/08/2007

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités