| Bug | Description |
|---|
| CVE-2004-1559 | Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 ... |
| CVE-2004-1584 | CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows ... |
| CVE-2005-1687 | SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and ... |
| CVE-2005-1688 | Wordpress 1.5 and earlier allows remote attackers to obtain sensitive ... |
| CVE-2005-1810 | SQL injection vulnerability in template-functions-category.php in ... |
| CVE-2005-2107 | Multiple cross-site scripting (XSS) vulnerabilities in post.php in ... |
| CVE-2005-2108 | SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and ... |
| CVE-2005-2109 | wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers ... |
| CVE-2005-2110 | WordPress 1.5.1.2 and earlier allows remote attackers to obtain ... |
| CVE-2005-2612 | Direct code injection vulnerability in WordPress 1.5.1.3 and earlier ... |
| CVE-2005-3330 | The _httpsrequest function in Snoopy 1.2, as used in products such as ... |
| CVE-2005-4463 | WordPress before 1.5.2 allows remote attackers to obtain sensitive ... |
| CVE-2005-4600 | Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE ... |
| CVE-2006-0985 | Multiple cross-site scripting (XSS) vulnerabilities in the "post ... |
| CVE-2006-0986 | WordPress 2.0.1 and earlier allows remote attackers to obtain ... |
| CVE-2006-1012 | SQL injection vulnerability in WordPress 1.5.2, and possibly other ... |
| CVE-2006-1263 | Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in ... |
| CVE-2006-1796 | Cross-site scripting (XSS) vulnerability in the paging links ... |
| CVE-2006-2667 | Direct static code injection vulnerability in WordPress 2.0.2 and ... |
| CVE-2006-2702 | vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows ... |
| CVE-2006-3389 | index.php in WordPress 2.0.3 allows remote attackers to obtain ... |
| CVE-2006-3390 | WordPress 2.0.3 allows remote attackers to obtain the installation ... |
| CVE-2006-4028 | Multiple unspecified vulnerabilities in WordPress before 2.0.4 have ... |
| CVE-2006-4208 | Directory traversal vulnerability in wp-db-backup.php in Skippy ... |
| CVE-2006-4743 | WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain ... |
| CVE-2006-5705 | Multiple directory traversal vulnerabilities in ... |
| CVE-2006-6016 | wp-admin/user-edit.php in WordPress before 2.0.5 allows remote ... |
| CVE-2006-6017 | WordPress before 2.0.5 does not properly store a profile containing a ... |
| CVE-2006-6808 | Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in ... |
| CVE-2007-0106 | Cross-site scripting (XSS) vulnerability in the CSRF protection scheme ... |
| CVE-2007-0107 | WordPress before 2.0.6, when mbstring is enabled for PHP, decodes ... |
| CVE-2007-0109 | wp-login.php in WordPress 2.0.5 and earlier displays different error ... |
| CVE-2007-0233 | wp-trackback.php in WordPress 2.0.6 and earlier does not properly ... |
| CVE-2007-0262 | WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify ... |
| CVE-2007-0539 | The wp_remote_fopen function in WordPress before 2.1 allows remote ... |
| CVE-2007-0540 | WordPress allows remote attackers to cause a denial of service ... |
| CVE-2007-0541 | WordPress allows remote attackers to determine the existence of ... |
| CVE-2007-1049 | Cross-site scripting (XSS) vulnerability in the wp_explain_nonce ... |
| CVE-2007-1230 | Multiple cross-site scripting (XSS) vulnerabilities in ... |
| CVE-2007-1244 | Cross-site request forgery (CSRF) vulnerability in the AdminPanel in ... |
| CVE-2007-1277 | WordPress 2.1.1, as downloaded from some official distribution sites ... |
| CVE-2007-1409 | WordPress allows remote attackers to obtain sensitive information via ... |
| CVE-2007-1599 | wp-login.php in WordPress allows remote attackers to redirect ... |
| CVE-2007-1622 | Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in ... |
| CVE-2007-1732 | ** DISPUTED ** ... |
| CVE-2007-1893 | xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows ... |
| CVE-2007-1894 | Cross-site scripting (XSS) vulnerability in ... |
| CVE-2007-1897 | SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, ... |
| CVE-2007-2383 | The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data ... |
| CVE-2007-2627 | Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, ... |
| CVE-2007-2714 | Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet ... |
| CVE-2007-2821 | SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress ... |
| CVE-2007-3140 | SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows ... |
| CVE-2007-3215 | PHPMailer 1.7, when configured to use sendmail, allows remote ... |
| CVE-2007-3238 | Cross-site scripting (XSS) vulnerability in functions.php in the ... |
| CVE-2007-3543 | Unrestricted file upload vulnerability in WordPress before 2.2.1 and ... |
| CVE-2007-3544 | Unrestricted file upload vulnerability in (1) wp-app.php and (2) ... |
| CVE-2007-3639 | WordPress before 2.2.2 allows remote attackers to redirect visitors to ... |
| CVE-2007-4153 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 ... |
| CVE-2007-4154 | SQL injection vulnerability in options.php in WordPress 2.2.1 allows ... |
| CVE-2007-4165 | Cross-site scripting (XSS) vulnerability in index.php in the Blue ... |
| CVE-2007-4483 | Cross-site scripting (XSS) vulnerability in index.php in the WordPress ... |
| CVE-2007-4893 | wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress ... |
| CVE-2007-4894 | Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and ... |
| CVE-2007-5105 | Cross-site scripting (XSS) vulnerability in wp-register.php in ... |
| CVE-2007-5106 | Cross-site scripting (XSS) vulnerability in wp-register.php in ... |
| CVE-2007-5710 | Cross-site scripting (XSS) vulnerability in ... |
| CVE-2007-6013 | Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash ... |
| CVE-2007-6318 | SQL injection vulnerability in wp-includes/query.php in WordPress ... |
| CVE-2008-0192 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 ... |
| CVE-2008-0193 | Cross-site scripting (XSS) vulnerability in wp-db-backup.php in ... |
| CVE-2008-0194 | Directory traversal vulnerability in wp-db-backup.php in WordPress ... |
| CVE-2008-0195 | WordPress 2.0.11 and earlier allows remote attackers to obtain ... |
| CVE-2008-0196 | Multiple directory traversal vulnerabilities in WordPress 2.0.11 and ... |
| CVE-2008-0664 | The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, ... |
| CVE-2008-1304 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 ... |
| CVE-2008-1502 | The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in ... |
| CVE-2008-1930 | The cookie authentication method in WordPress 2.5 relies on a hash of ... |
| CVE-2008-2068 | Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows ... |
| CVE-2008-2146 | wp-includes/vars.php in Wordpress before 2.2.3 does not properly ... |
| CVE-2008-2392 | Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier ... |
| CVE-2008-3233 | Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN ... |
| CVE-2008-3747 | The (1) get_edit_post_link and (2) get_edit_comment_link functions in ... |
| CVE-2008-4106 | WordPress before 2.6.2 does not properly handle MySQL warnings about ... |
| CVE-2008-4671 | Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in ... |
| CVE-2008-4769 | Directory traversal vulnerability in the get_category_template ... |
| CVE-2008-4796 | The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 ... |
| CVE-2008-5113 | WordPress 2.6.3 relies on the REQUEST superglobal array in certain ... |
| CVE-2008-5278 | Cross-site scripting (XSS) vulnerability in the self_link function in ... |
| CVE-2008-5695 | wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 ... |
| CVE-2008-6762 | Open redirect vulnerability in wp-admin/upgrade.php in WordPress, ... |
| CVE-2008-6767 | wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote ... |
| CVE-2008-7220 | Unspecified vulnerability in Prototype JavaScript framework ... |
| CVE-2009-2334 | wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not ... |
| CVE-2009-2335 | WordPress and WordPress MU before 2.8.1 exhibit different behavior for ... |
| CVE-2009-2336 | The forgotten mail interface in WordPress and WordPress MU before ... |
| CVE-2009-2431 | WordPress 2.7.1 places the username of a post's author in an HTML ... |
| CVE-2009-2432 | WordPress and WordPress MU before 2.8.1 allow remote attackers to ... |
| CVE-2009-2762 | wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to ... |
| CVE-2009-2851 | Cross-site scripting (XSS) vulnerability in the administrator ... |
| CVE-2009-2853 | Wordpress before 2.8.3 allows remote attackers to gain privileges via ... |
| CVE-2009-2854 | Wordpress before 2.8.3 does not check capabilities for certain ... |
| CVE-2009-3622 | Algorithmic complexity vulnerability in wp-trackback.php in WordPress ... |
| CVE-2009-3890 | Unrestricted file upload vulnerability in the wp_check_filetype ... |
| CVE-2009-3891 | Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in ... |
| CVE-2010-0682 | WordPress 2.9 before 2.9.2 allows remote authenticated users to read ... |
| CVE-2010-1619 | Cross-site scripting (XSS) vulnerability in the ... |
| CVE-2010-2230 | The KSES text cleaning filter in lib/weblib.php in Moodle before ... |
| CVE-2010-4257 | SQL injection vulnerability in the do_trackbacks function in ... |
| CVE-2010-4536 | Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used ... |
| CVE-2011-0700 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress ... |
| CVE-2011-0701 | wp-admin/async-upload.php in the media uploader in WordPress before ... |
| CVE-2011-3122 | Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before ... |
| CVE-2011-3125 | Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before ... |
| CVE-2011-3126 | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote ... |
| CVE-2011-3127 | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent ... |
| CVE-2011-3128 | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached ... |
| CVE-2011-3129 | The file upload functionality WordPress 3.1 before 3.1.3 and 3.2 ... |
| CVE-2011-3130 | wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before ... |
| CVE-2011-4956 | |
| CVE-2011-4957 | |
| CVE-2012-0287 | Cross-site scripting (XSS) vulnerability in wp-comments-post.php in ... |
| CVE-2012-2399 | Unspecified vulnerability in wp-includes/js/swfupload/swfupload.swf in ... |
| CVE-2012-2400 | Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress ... |
| CVE-2012-2401 | Plupload before 1.5.4, as used in wp-includes/js/plupload/ in ... |
| CVE-2012-2402 | wp-admin/plugins.php in WordPress before 3.3.2 allows remote ... |
| CVE-2012-2403 | wp-includes/formatting.php in WordPress before 3.3.2 attempts to ... |
| CVE-2012-2404 | wp-comments-post.php in WordPress before 3.3.2 supports offsite ... |
| TEMP-0000000-0CA7E3 | XSS in press-this of wordpress |
| TEMP-0369014-6AE03E | 'Cache' shell injection vulnerability |
| TEMP-0407116-23D9EF | wordpress unregister_globals workaround from 2.0.7 |
| TEMP-0606657-A0D78A | wordpress: insufficient permissions verification on XMLRPC interface |