VYPR
Unrated severityNVD Advisory· Published Apr 21, 2012· Updated Jun 16, 2026

CVE-2012-2399

CVE-2012-2399

Description

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

82
  • WordPress/WordPress80 versions
    cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 79 more
    • cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: <=3.3.1
    • cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.5:a:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.4:a:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.3:*:*:*:*:*:*:*
  • Range: <=2.2.0.1
  • Range: <=1.1

Patches

Vulnerability mechanics

References

15

News mentions

0

No linked articles in our index yet.