WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress 2.0.5 Vulnerabilities
CVE-2022-4973
CVE-2013-4144
CVE-2011-1762
WordPress <= 5.9.1 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress core <= 5.8.1 - Expired DST Root CA X3 Certificate issue
WordPress core <= 5.8 - Command injection vulnerability in the Lodash library
WordPress <= 5.7.1 - Object injection in PHPMailer vulnerability
CVE-2020-36326
WordPress core 4.7-5.7 - Sensitive Data Exposure vulnerability
WordPress <= 5.5.1 - XML-RPC Privilege Escalation vulnerability
WordPress <= 5.3 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress <= 5.2.3 - Multiple security issues (XSS, SSRF, Cache Poisoning)
WordPress core <= 5.2.2 - Cross-Site Scripting (XSS) vulnerability
WordPress 3.9-5.1 - Cross-Site Scripting (XSS) vulnerability
WordPress <= 5.0 - Authenticated File Delete vulnerability
WordPress <= 5.0 - Authenticated Post Type Bypass vulnerability
WordPress <= 5.0 - PHP Object Injection via Meta Data vulnerability
WordPress <= 5.0 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress <= 5.0 - Cross-Site Scripting (XSS) vulnerability that could affect plugins
WordPress <= 5.0 - User Activation Screen Search Engine Indexing
WordPress <= 5.0 - File Upload to XSS on Apache Web Servers vulnerability
WordPress <=4.9.4 - Vulnerable due to "localhost" default parameter
WordPress <=4.9.4 - Use Safe Redirect for Login
WordPress <=4.9.4 - Escape Version in Generator Tag
WordPress 3.7-4.9.1 - Cross-Site Scripting vulnerability
WordPress <=4.9 - Authenticated JavaScript File Upload vulnerability
WordPress <=4.8.2 - potential SQL injection (SQLi), $wpdb->prepare() issue, possible unsafe queries
WordPress <=4.8.1 - SQL injection (SQLi) vulnerability
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (oEmbed)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (visual editor)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (plugin editor)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (template names)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (link modal)
WordPress <=4.8.1 - Path traversal vulnerability (file unzipping code)
WordPress <=4.8.1 - Path traversal vulnerability (customizer)
WordPress <=4.8.1 - Open redirect vulnerability (user and term edit screens)
WordPress <= 4.5.3 - Path traversal
WordPress <= 4.2 - Stored XSS
WordPress Core < 3.8.2 - SQL Injection
CVE-2012-6633
CVE-2011-5270
CVE-2010-5293
CVE-2010-5294
CVE-2010-5295
CVE-2010-5296
CVE-2010-5297
CVE-2012-6634
CVE-2012-6635
CVE-2013-7233
WordPress <=3.6 - URL Redirect Restriction Bypass
CVE-2013-4338
CVE-2013-5738
CVE-2013-5739
CVE-2013-4339
CVE-2013-4340
WordPress vulnerable to cross-site scripting
CVE-2012-3414
CVE-2013-2199
CVE-2013-0235
CVE-2013-2201
CVE-2013-2202
CVE-2013-2200
CVE-2013-0236
CVE-2013-0237
CVE-2013-2203
CVE-2013-2204
CVE-2013-2205
CVE-2013-2173
CVE-2012-5868
CVE-2012-4448
WordPress 3.4.2 - Multiple Path Dislosure Vulnerabilities
CVE-2010-5106
CVE-2012-4421
CVE-2012-4422
WordPress Core < 3.4.2 - Cross-Site Scripting
CVE-2012-3384
CVE-2012-3385
CVE-2011-4956
CVE-2011-4957
CVE-2012-1936
CVE-2012-2400
CVE-2012-2401
CVE-2012-2402
CVE-2012-2403
CVE-2012-2404
CVE-2012-0782
CVE-2012-0937
CVE-2011-4898
CVE-2011-4899
CVE-2012-0287
WordPress vulnerable to arbitrary PHP code execution
WordPress Japanese vulnerable to cross-site scripting
WordPress DEV Blogs MU 1.2.6 - HTML Injection Vulnerability
WordPress Regular Subscriber Plugin 3.1.x - HTML Injection Vulnerability
CVE-2011-3122
CVE-2011-3125
CVE-2011-3126
CVE-2011-3127
CVE-2011-3128
CVE-2011-3129
CVE-2011-3130
WordPress 3.1.3 - SQL Injection Vulnerabilities
CVE-2011-0700
CVE-2011-0701
CVE-2010-4536
WordPress 3.0.3 - Stored XSS (IE6/7 NS8.1)
CVE-2010-4257
CVE-2010-0682
WordPress <= 2.9 - DoS (0day)
WordPress Core <= 2.8.5 - Arbitrary File Upload
WordPress Core <= 2.8.5 - Cross-Site Scripting
WordPress 2.0 - 2.7.1 - Module Configuration Security Bypass Vulnerability
CVE-2009-3622
WordPress Core & WordPress MU < 2.8.1 - Full Path Disclosure
CVE-2009-2854
CVE-2009-2851
CVE-2009-2853
CVE-2009-2762
CVE-2009-2334
CVE-2009-2431
CVE-2009-2336
CVE-2009-2335
CVE-2008-6762
CVE-2008-6767
CVE-2009-1030
WordPress Core < 2.6.5 - Cross-Site Scripting
CVE-2008-5695
CVE-2008-5113
CVE-2008-4769
CVE-2008-4671
CVE-2008-4106
CVE-2008-4107
CVE-2008-3747
CVE-2008-3233
CVE-2008-2510
CVE-2008-2392
CVE-2008-2146
CVE-2008-2068
CVE-2008-1930
CVE-2008-1304
CVE-2008-0664
CVE-2008-0191
CVE-2008-0192
CVE-2008-0193
CVE-2008-0195
CVE-2008-0196
WordPress Core 1.5 - 2.3.1 - Authorization Bypass
CVE-2007-6318
CVE-2007-5710
CVE-2007-4893
CVE-2007-4894
WordPress Core < 2.2.2 - Open Redirect
WordPress Core <= 2.2.1 - Cross-Site Scripting
WordPress Core <= 2.2.1 - Authenticated (Admin+) Cross-Site Scripting
WordPress Core <= 2.2.1 - SQL Injection
WordPress Core <= 2.2 - Arbitrary File Upload
WordPress Core <= 2.2.1 - Arbitrary File Upload
WordPress Core <= 2.2 - SQL Injection
WordPress Core <= 2.2 - Cross-Site Scripting
CVE-2007-3238
CVE-2007-2821
CVE-2007-1893
CVE-2007-1894
CVE-2007-1897
WordPress Core < 2.0.10 - Open Redirect
WordPress Core <= 2.1.2 - Cross-Site Scripting
CVE-2007-1732
CVE-2007-1409
CVE-2007-1277
CVE-2007-1244
CVE-2007-1230
WordPress Core 2.1.1 - Supply Chain Compromise
CVE-2007-1049
CVE-2007-0539
CVE-2007-0540
CVE-2007-0541
CVE-2007-0262
WordPress Core < 2.0.7 - SQL Injection
CVE-2007-0106
CVE-2007-0107
CVE-2007-0109
WordPress Core <= 2.0.5 - Cross-Site Scripting
WordPress Core 2.0.2 - 2.0.5 - Sensitive Information Disclosure
CVE-2006-6016
CVE-2006-6017
CVE-2006-5705