Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 3.7.4 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-9033
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote malicious users to hijack the authentication of arbitrary users for requests that reset passwords.
Wordpress Wordpress 3.7.4
Wordpress Wordpress 3.8.4
Wordpress Wordpress 3.9.2
Wordpress Wordpress 4.0
7.5
CVSSv3
CVE-2017-14719
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
Wordpress Wordpress 3.0
Wordpress Wordpress 3.0.1
Wordpress Wordpress 3.0.2
Wordpress Wordpress 3.0.3
Wordpress Wordpress 3.0.4
Wordpress Wordpress 3.0.5
Wordpress Wordpress 3.0.6
Wordpress Wordpress 3.1
Wordpress Wordpress 3.1.1
Wordpress Wordpress 3.1.2
Wordpress Wordpress 3.1.3
Wordpress Wordpress 3.1.4
1 Github repository
NA
CVE-2012-5310
SQL injection vulnerability in the WP e-Commerce plugin prior to 3.8.7.6 for WordPress allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Getshopped Wp E-commerce
Getshopped Wp E-commerce 3.6.5
Getshopped Wp E-commerce 3.6.6
Getshopped Wp E-commerce 3.6.7
Getshopped Wp E-commerce 3.6.8
Getshopped Wp E-commerce 3.6.9
Getshopped Wp E-commerce 3.6.10
Getshopped Wp E-commerce 3.6.11
Getshopped Wp E-commerce 3.6.12
Getshopped Wp E-commerce 3.6.13
Getshopped Wp E-commerce 3.7
Getshopped Wp E-commerce 3.7.1
NA
CVE-2011-5104
Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote malicious users to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obt...
Getshopped Wp E-commerce
Getshopped Wp E-commerce 3.6.5
Getshopped Wp E-commerce 3.6.6
Getshopped Wp E-commerce 3.6.7
Getshopped Wp E-commerce 3.6.8
Getshopped Wp E-commerce 3.6.9
Getshopped Wp E-commerce 3.6.10
Getshopped Wp E-commerce 3.6.11
Getshopped Wp E-commerce 3.6.12
Getshopped Wp E-commerce 3.6.13
Getshopped Wp E-commerce 3.7
Getshopped Wp E-commerce 3.7.1
6.1
CVSSv3
CVE-2020-11023
In jQuery versions greater than or equal to 1.0.3 and prior to 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted c...
Jquery Jquery
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Drupal Drupal
Oracle Application Express
Oracle Application Testing Suite 13.3.0.1
Oracle Banking Enterprise Collections
Oracle Banking Platform
Oracle Business Intelligence 5.9.0.0.0
Oracle Communications Analytics 12.1.1
9 Github repositories
6.1
CVSSv3
CVE-2020-11022
In jQuery versions greater than or equal to 1.2 and prior to 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuer...
Jquery Jquery
Drupal Drupal
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Oracle Agile Product Lifecycle Management For Process 6.2.0.0
Oracle Application Testing Suite 13.3.0.1
Oracle Banking Digital Experience 18.1
Oracle Banking Digital Experience 18.2
Oracle Banking Digital Experience 18.3
Oracle Banking Digital Experience 19.1
10 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-12326
CVE-2024-44852
XSS
privilege escalation
CSRF
CVE-2024-12115
CVE-2024-38925
CVE-2024-38144
CVE-2024-6387
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started