Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 2.0.10 vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2008-6762
Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.
Wordpress Wordpress 2.6
890
VMScore
CVE-2008-6767
wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote malicious users to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.
Wordpress Wordpress 2.6
356
VMScore
CVE-2008-5113
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote malicious users to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete us...
Wordpress Wordpress 2.6.3
890
VMScore
CVE-2008-4796
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and previous versions, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote malicious users to execute arbitrary commands vi...
Snoopy Project Snoopy
Debian Debian Linux 5.0
Debian Debian Linux 4.0
Nagios Nagios
Wordpress Wordpress
685
VMScore
CVE-2013-4240
Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin prior to 2.0.11 for WordPress allow remote malicious users to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2)...
Hitmyserver Hms Testimonials 1.1
Hitmyserver Hms Testimonials 1.2
Hitmyserver Hms Testimonials 1.3
Hitmyserver Hms Testimonials 1.4
Hitmyserver Hms Testimonials 1.4.1
Hitmyserver Hms Testimonials 1.5
Hitmyserver Hms Testimonials 1.6
Hitmyserver Hms Testimonials 1.6.1
Hitmyserver Hms Testimonials 1.6.2
Hitmyserver Hms Testimonials 1.7
Hitmyserver Hms Testimonials 1.7.1
Hitmyserver Hms Testimonials 2.0
Hitmyserver Hms Testimonials 2.0.1
Hitmyserver Hms Testimonials 2.0.2
Hitmyserver Hms Testimonials 2.0.3
Hitmyserver Hms Testimonials 2.0.4
Hitmyserver Hms Testimonials 2.0.5
Hitmyserver Hms Testimonials 2.0.6
Hitmyserver Hms Testimonials 2.0.7
Hitmyserver Hms Testimonials 2.0.8
Hitmyserver Hms Testimonials 2.0.9
Hitmyserver Hms Testimonials
1 EDB exploit
435
VMScore
CVE-2013-4241
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin prior to 2.0.11 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-tes...
Hitmyserver Hms Testimonials
1 EDB exploit
1000
VMScore
CVE-2012-3576
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin prior to 2.5.30 for WordPress allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads...
Jquindlen Wpstorecart
Jquindlen Wpstorecart 0.62
Jquindlen Wpstorecart 1.0.0
Jquindlen Wpstorecart 2.0.0
Jquindlen Wpstorecart 2.0.1
Jquindlen Wpstorecart 2.0.2
Jquindlen Wpstorecart 2.0.3
Jquindlen Wpstorecart 2.0.4
Jquindlen Wpstorecart 2.0.5
Jquindlen Wpstorecart 2.0.6
Jquindlen Wpstorecart 2.0.7
Jquindlen Wpstorecart 2.0.8
Jquindlen Wpstorecart 2.0.9
Jquindlen Wpstorecart 2.0.10
Jquindlen Wpstorecart 2.0.11
Jquindlen Wpstorecart 2.0.12
Jquindlen Wpstorecart 2.0.13
Jquindlen Wpstorecart 2.1.0
Jquindlen Wpstorecart 2.1.1
Jquindlen Wpstorecart 2.1.2
Jquindlen Wpstorecart 2.1.3
Jquindlen Wpstorecart 2.1.4
1 EDB exploit
383
VMScore
CVE-2008-1502
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare prior to 1.4.003, Moodle prior to 1.8.5, and other products, allows remote malicious users to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string contai...
Egroupware Egroupware 1.0
Moodle Moodle 1.5.2
Moodle Moodle 1.6.1
Moodle Moodle 1.8.2
Egroupware Egroupware
Moodle Moodle 1.2.1
Moodle Moodle 1.4.2
Moodle Moodle 1.6.5
Moodle Moodle 1.3.3
Moodle Moodle 1.4.3
Egroupware Egroupware 1.0.6
Moodle Moodle 1.4.5
Moodle Moodle 1.7.6
Moodle Moodle 1.6.2
Moodle Moodle 1.7.1
Moodle Moodle
Egroupware Egroupware 1.2.106-2
Moodle Moodle 1.8.3
Moodle Moodle 1.3.2
Egroupware Egroupware 1.0.3
Moodle Moodle 1.6.4
Moodle Moodle 1.1.1
383
VMScore
CVE-2014-3841
Cross-site scripting (XSS) vulnerability in the Contact Bank plugin prior to 2.0.20 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the Label field, related to form layout configuration. NOTE: some of these details are obtained from third pa...
Tech-banker Contact Bank
Tech-banker Contact Bank 2.0.0
Tech-banker Contact Bank 2.0.1
Tech-banker Contact Bank 2.0.2
Tech-banker Contact Bank 2.0.3
Tech-banker Contact Bank 2.0.4
Tech-banker Contact Bank 2.0.5
Tech-banker Contact Bank 2.0.6
Tech-banker Contact Bank 2.0.7
Tech-banker Contact Bank 2.0.8
Tech-banker Contact Bank 2.0.9
Tech-banker Contact Bank 2.0.10
Tech-banker Contact Bank 2.0.11
Tech-banker Contact Bank 2.0.12
Tech-banker Contact Bank 2.0.13
Tech-banker Contact Bank 2.0.14
Tech-banker Contact Bank 2.0.15
Tech-banker Contact Bank 2.0.16
Tech-banker Contact Bank 2.0.17
Tech-banker Contact Bank 2.0.18
383
VMScore
CVE-2018-18379
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin prior to 2.0.10 for WordPress has XSS.
Elementor Elementor Page Builder
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
NEXT »