Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
wordpress wordpress mu vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-4671
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters....
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.0
Wordpress Wordpress Mu
1 EDB exploit available
NA
CVE-2009-1030
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header....
Wordpress Wordpress Mu 1.0
Wordpress Wordpress Mu 1.2.4
Wordpress Wordpress Mu 1.2.5a
Wordpress Wordpress Mu 2.6.3
Wordpress Wordpress Mu 2.6.5
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.1.1
Wordpress Wordpress Mu 1.1
Wordpress Wordpress Mu 1.5
Wordpress Wordpress Mu 1.5.1
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.3.2
Wordpress Wordpress Mu 1.3.3
Wordpress Wordpress Mu 2.7
Wordpress Wordpress Mu
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.2
Wordpress Wordpress Mu 1.2.1
Wordpress Wordpress Mu 2.6.1
Wordpress Wordpress Mu 2.6.2
1 EDB exploit available
NA
CVE-2009-2432
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message....
Wordpress Wordpress 2.6
Wordpress Wordpress 2.5.1
Wordpress Wordpress 2.3
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.1
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 1.5.1
Wordpress Wordpress 1.2.1
Wordpress Wordpress 1.2-mingus
Wordpress Wordpress 1.0.2
Wordpress Wordpress 1.0.1-miles
Wordpress Wordpress 0.72
Wordpress Wordpress 0.711
Wordpress Wordpress 0.6.2
Wordpress Wordpress 2.6.1
Wordpress Wordpress 2.6.3
Wordpress Wordpress Mu 1.2.4
Wordpress Wordpress Mu 1.5
Wordpress Wordpress Mu 2.6
Wordpress Wordpress 2.3.3
Wordpress Wordpress 2.3.2
Wordpress Wordpress 2.2.2
Wordpress Wordpress 2.2.1
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 1.6
Wordpress Wordpress 1.5.2
Wordpress Wordpress 1.4
Wordpress Wordpress 1.3.1
Wordpress Wordpress 1.0
Wordpress Wordpress 0.7
Wordpress Wordpress Mu 1.2
Wordpress Wordpress 2.5
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.5
Wordpress Wordpress 1.2-delta
Wordpress Wordpress 1.2
Wordpress Wordpress 1.0.1
Wordpress Wordpress 1.0-platinum
Wordpress Wordpress 0.71-gold
Wordpress Wordpress 0.71
Wordpress Wordpress Mu 1.1
Wordpress Wordpress Mu 1.1.1
Wordpress Wordpress Mu 1.2.5a
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 2.6.1
Wordpress Wordpress Mu 2.6.2
Wordpress Wordpress Mu 1.2.1
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.3.2
Wordpress Wordpress Mu 2.6.3
Wordpress Wordpress Mu 2.6.5
Wordpress Wordpress 2.3.1
Wordpress Wordpress 2.2.0
Wordpress Wordpress 2.2
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.0.2-blakey
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.3.3
Wordpress Wordpress Mu 1.5.1
Wordpress Wordpress Mu
Wordpress Wordpress
Wordpress Wordpress 2.6.5
NA
CVE-2009-2334
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify...
Wordpress Wordpress 2.3.3
Wordpress Wordpress 2.3.2
Wordpress Wordpress 2.2.2
Wordpress Wordpress 2.2.1
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.1
Wordpress Wordpress 2.6
Wordpress Wordpress 2.3.1
Wordpress Wordpress 2.2.0
Wordpress Wordpress 2.2
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.2.1
Wordpress Wordpress 2.5.1
Wordpress Wordpress 2.5
Wordpress Wordpress 2.3
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 1.5.1
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.2-mingus
Wordpress Wordpress 1.2-delta
Wordpress Wordpress 1.0.2
Wordpress Wordpress 1.0.1-miles
Wordpress Wordpress 0.711
Wordpress Wordpress 0.71-gold
Wordpress Wordpress 2.6.1
Wordpress Wordpress 2.6.3
Wordpress Wordpress Mu 1.2.4
Wordpress Wordpress Mu 2.6
Wordpress Wordpress Mu 2.6.1
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 1.6
Wordpress Wordpress 1.5.2
Wordpress Wordpress 1.3.1
Wordpress Wordpress 1.2
Wordpress Wordpress 1.0
Wordpress Wordpress 0.72
Wordpress Wordpress 0.6.2
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress Mu 1.2
Wordpress Wordpress Mu 1.2.1
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.3.2
Wordpress Wordpress Mu 1.3.3
Wordpress Wordpress Mu 2.6.5
Wordpress Wordpress Mu
Wordpress Wordpress 1.0.2-blakey
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.5.1
Wordpress Wordpress Mu 1.5
Wordpress Wordpress
Wordpress Wordpress 2.6.5
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0
Wordpress Wordpress 1.5
Wordpress Wordpress 1.4
Wordpress Wordpress 1.0.1
Wordpress Wordpress 1.0-platinum
Wordpress Wordpress 0.71
Wordpress Wordpress 0.7
Wordpress Wordpress Mu 1.1
Wordpress Wordpress Mu 1.1.1
Wordpress Wordpress Mu 1.2.5a
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 2.6.2
Wordpress Wordpress Mu 2.6.3
1 EDB exploit available
NA
CVE-2009-2335
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue,...
Wordpress Wordpress
Wordpress Wordpress Mu
1 EDB exploit available
1 Metasploit module available
6 Github repositories available
NA
CVE-2007-3544
Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom...
Wordpress Wordpress
Wordpress Wordpress Mu
NA
CVE-2007-3543
Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending...
Wordpress Wordpress Mu
Wordpress Wordpress
NA
CVE-2009-2336
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the...
Wordpress Wordpress
Wordpress Wordpress Mu
1 Metasploit module available
NA
CVE-2008-5695
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP...
Wordpress Wordpress
Wordpress Wordpress Mu
1 EDB exploit available
NA
CVE-2007-4544
Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field)....
Wordpress Wordpress Mu
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-5172
CVE-2023-44023
CVE-2023-30845
elevation of privilege
injection
CVE-2023-43234
CVE-2023-41991
cross-site request forgery
seacms
CVE-2023-5197
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »