VYPR

WordPress

by WordPress

Source repositories

CVEs (374)

  • CVE-2017-9061MedMay 18, 2017
    risk 0.33cvss 6.1epss 0.03

    In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

  • CVE-2017-6818MedMar 12, 2017
    risk 0.33cvss 6.1epss 0.04

    In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.

  • CVE-2017-6815MedMar 12, 2017
    risk 0.33cvss 6.1epss 0.04

    In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

  • CVE-2017-5612MedJan 30, 2017
    risk 0.33cvss 6.1epss 0.04

    Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

  • CVE-2016-5834MedJun 29, 2016
    risk 0.33cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

  • CVE-2016-5833MedJun 29, 2016
    risk 0.33cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than…

  • CVE-2016-4567MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.09

    Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by…

  • CVE-2016-4566MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

  • CVE-2016-1564MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.

  • CVE-2015-8834MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability…

  • CVE-2015-5714MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.09

    Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

  • CVE-2022-4973MedOct 16, 2024
    risk 0.32cvss 4.9epss 0.00

    WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary…

  • CVE-2019-16223MedSep 11, 2019
    risk 0.32cvss 5.4epss 0.05

    WordPress before 5.2.3 allows XSS in post previews by authenticated users.

  • CVE-2025-58674MedSep 23, 2025
    risk 0.31cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author…

  • CVE-2024-2643MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting…

  • CVE-2020-11029MedApr 30, 2020
    risk 0.31cvss 5.8epss 0.02

    In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release…

  • CVE-2020-11028MedApr 30, 2020
    risk 0.31cvss 5.8epss 0.02

    In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3,…

  • CVE-2020-11025MedApr 30, 2020
    risk 0.31cvss 5.8epss 0.02

    In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously…

  • CVE-2019-16781MedDec 26, 2019
    risk 0.31cvss 5.8epss 0.01

    In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.

  • CVE-2019-16780MedDec 26, 2019
    risk 0.31cvss 5.8epss 0.02

    WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an…

Page 7 of 19