Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 3.7.4 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-9033
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote malicious users to hijack the authentication of arbitrary users for requests that reset passwords.
Wordpress Wordpress 3.7.4
Wordpress Wordpress 3.8.4
Wordpress Wordpress 3.9.2
Wordpress Wordpress 4.0
7.5
CVSSv3
CVE-2017-14719
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
Wordpress Wordpress 4.7.1
Wordpress Wordpress 4.7.2
Wordpress Wordpress 4.6.6
Wordpress Wordpress 4.6.5
Wordpress Wordpress 4.6.4
Wordpress Wordpress 4.5.7
Wordpress Wordpress 4.5.6
Wordpress Wordpress 4.5
Wordpress Wordpress 4.4.9
Wordpress Wordpress 4.4.11
Wordpress Wordpress 4.4.10
Wordpress Wordpress 4.3.5
Wordpress Wordpress 4.3.4
Wordpress Wordpress 4.3
Wordpress Wordpress 4.2.9
Wordpress Wordpress 4.2.16
Wordpress Wordpress 4.2.15
Wordpress Wordpress 4.2
Wordpress Wordpress 4.1.9
Wordpress Wordpress 4.1.2
Wordpress Wordpress 4.1.19
Wordpress Wordpress 4.1.11
2 Github repositories
NA
CVE-2011-5104
Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote malicious users to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obt...
Getshopped Wp E-commerce 3.8.6
Getshopped Wp E-commerce 3.8.5
Getshopped Wp E-commerce 3.8
Getshopped Wp E-commerce 3.7.8.1
Getshopped Wp E-commerce 3.7.8
Getshopped Wp E-commerce 3.7.7
Getshopped Wp E-commerce 3.7.6.2
Getshopped Wp E-commerce 3.7.6.1
Getshopped Wp E-commerce 3.7
Getshopped Wp E-commerce 3.7.5.3
Getshopped Wp E-commerce 3.7.5
Getshopped Wp E-commerce 3.6.13
Getshopped Wp E-commerce 3.6.12
Getshopped Wp E-commerce 3.8.4
Getshopped Wp E-commerce 3.8.3
Getshopped Wp E-commerce 3.7.6.9
Getshopped Wp E-commerce 3.7.6.7
Getshopped Wp E-commerce 3.7.6
Getshopped Wp E-commerce 3.7.5.2
Getshopped Wp E-commerce 3.7.5.1
Getshopped Wp E-commerce 3.7.4
Getshopped Wp E-commerce 3.6.11
NA
CVE-2012-5310
SQL injection vulnerability in the WP e-Commerce plugin prior to 3.8.7.6 for WordPress allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Getshopped Wp E-commerce 3.8.7.3
Getshopped Wp E-commerce 3.8.7.2
Getshopped Wp E-commerce 3.8.4
Getshopped Wp E-commerce 3.8.7.1
Getshopped Wp E-commerce 3.8.1
Getshopped Wp E-commerce 3.8.2
Getshopped Wp E-commerce 3.7.6.4
Getshopped Wp E-commerce 3.7.6.3
Getshopped Wp E-commerce 3.7
Getshopped Wp E-commerce 3.7.2
Getshopped Wp E-commerce 3.7.6
Getshopped Wp E-commerce 3.7.5
Getshopped Wp E-commerce 3.6.5
Getshopped Wp E-commerce 3.6.8
Getshopped Wp E-commerce
Getshopped Wp E-commerce 3.8
Getshopped Wp E-commerce 3.8.6.1
Getshopped Wp E-commerce 3.8.7
Getshopped Wp E-commerce 3.7.8.2
Getshopped Wp E-commerce 3.7.6.2
Getshopped Wp E-commerce 3.7.6.1
Getshopped Wp E-commerce 3.7.1
6.1
CVSSv3
CVE-2020-11023
In jQuery versions greater than or equal to 1.0.3 and prior to 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted c...
Jquery Jquery
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Drupal Drupal
Oracle Weblogic Server 12.1.3.0.0
Oracle Hyperion Financial Reporting 11.1.2.4
Oracle Weblogic Server 12.2.1.3.0
Oracle Webcenter Sites 12.2.1.3.0
Oracle Application Testing Suite 13.3.0.1
Oracle Communications Operations Monitor 3.4
Oracle Weblogic Server 12.2.1.4.0
Oracle Webcenter Sites 12.2.1.4.0
Oracle Weblogic Server 14.1.1.0.0
Oracle Communications Interactive Session Recorder
Oracle Communications Element Manager 8.2.0
Oracle Communications Element Manager 8.2.1
Oracle Communications Element Manager 8.1.1
Oracle Application Express
Oracle Rest Data Services 12.2.0.1
Oracle Rest Data Services 12.1.0.2
12 Github repositories
6.1
CVSSv3
CVE-2020-11022
In jQuery versions greater than or equal to 1.2 and prior to 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuer...
Jquery Jquery
Drupal Drupal
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Oracle Weblogic Server 12.1.3.0.0
Oracle Jdeveloper 11.1.1.9.0
Oracle Retail Back Office 14.1
Oracle Retail Back Office 14.0
Oracle Peoplesoft Enterprise Peopletools 8.56
Oracle Weblogic Server 10.3.6.0.0
Oracle Communications Webrtc Session Controller 7.2
Oracle Weblogic Server 12.2.1.3.0
Oracle Agile Product Lifecycle Management For Process 6.2.0.0
Oracle Peoplesoft Enterprise Peopletools 8.57
Oracle Application Testing Suite 13.3.0.1
Oracle Retail Returns Management 14.0
Oracle Retail Returns Management 14.1
Oracle Jdeveloper 12.2.1.3.0
Oracle Policy Automation Connector For Siebel 10.4.6
Oracle Financial Services Market Risk Measurement And Management 8.0.6
12 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started