WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress 3.7.41 Vulnerabilities
CVE-2021-29476
CVE-2022-3590
CVE-2022-43500
CVE-2022-43497
WordPress Core < 6.0.3 - Shared User Instance Weakness
WordPress Core < 6.0.3 - Open Redirect
WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak)
WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer
WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API
WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection
WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php
WordPress Core < 6.0.3 - Information Disclosure (Email Address)
WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments
WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query
WordPress Core < 6.0.2 - Authenticated SQL Injection
WordPress Core < 6.0.2 - Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors
WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function
WordPress Core 5.9 - 5.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Core < 5.9.1 - jQuery Prototype Pollution
WordPress Core < 5.8.2 - ca-bundle.crt contains expired certificate DST Root CA X3
WordPress Core < 5.8.1 - LoDash Update
CVE-2021-20083
CVE-2018-14028
CVE-2017-8295
WordPress Core < 3.8.2 - SQL Injection