Search CVE reports


Toggle filters

41 – 50 of 371 results


CVE-2022-21663

Low priority
Needs evaluation

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2022-21662

Medium priority
Needs evaluation

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2022-21661

Medium priority
Needs evaluation

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-44223

Medium priority
Needs evaluation

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-39203

Low priority
Needs evaluation

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-39202

Medium priority
Needs evaluation

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-39201

Low priority
Needs evaluation

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-39200

Low priority
Needs evaluation

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-29476

Medium priority
Needs evaluation

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-29450

Low priority
Needs evaluation

Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages