Vulnerabilities > Wordpress > Wordpress
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-06-01 | CVE-2005-1810 | SQL Injection vulnerability in Wordpress 1.5.1 SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php. | 7.5 |
2005-05-20 | CVE-2005-1687 | Unspecified vulnerability in Wordpress 1.5 SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. | 7.5 |
2005-05-02 | CVE-2005-1102 | Cross-Site Scripting vulnerability in WordPress Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post. network wordpress | 6.8 |
2004-12-31 | CVE-2004-1584 | Unspecified vulnerability in Wordpress 1.2 CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter. | 5.0 |
2004-12-31 | CVE-2004-1559 | Cross-Site Scripting vulnerability in Wordpress 1.2 Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php. network wordpress | 4.3 |