CVE-2018-19296high · CVSS 8.8 — PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
CVE-2019-8943medium · CVSS 6.5 — WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output ima
CVE-2019-9787high · CVSS 8.8 — WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf
CVE-2019-16217medium · CVSS 6.1 — WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
CVE-2019-16218medium · CVSS 6.1 — WordPress before 5.2.3 allows XSS in stored comments.
CVE-2019-16219medium · CVSS 6.1 — WordPress before 5.2.3 allows XSS in shortcode previews.
CVE-2019-16220medium · CVSS 6.1 — In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open r
CVE-2019-16221medium · CVSS 6.1 — WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVE-2019-16222medium · CVSS 6.1 — WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site s
CVE-2019-16223medium · CVSS 5.4 — WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-17669critical · CVSS 9.8 — WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of
CVE-2019-17670critical · CVSS 9.8 — WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation
CVE-2019-17671medium · CVSS 5.3 — In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVE-2019-17672medium · CVSS 6.1 — WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17673high · CVSS 7.5 — WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
CVE-2019-17674medium · CVSS 5.4 — WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVE-2019-17675high · CVSS 8.8 — WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CS
CVE-2019-16780medium · CVSS 5.8 — WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is
CVE-2019-16781medium · CVSS 5.8 — In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, whi
CVE-2019-20041critical · CVSS 9.8 — wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass
CVE-2019-20042medium · CVSS 6.1 — In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a
CVE-2019-20043medium · CVSS 4.3 — In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the r
CVE-2020-11025medium · CVSS 5.8 — In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code
CVE-2020-11026high · CVSS 8.7 — In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon
CVE-2020-11027medium · CVSS 6.1 — In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be
CVE-2020-11028medium · CVSS 5.8 — In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specif
CVE-2020-11029medium · CVSS 5.8 — In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site
CVE-2020-11030medium · CVSS 6.4 — In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the
CVE-2020-4046medium · CVSS 5.4 — In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inj
CVE-2020-4047medium · CVSS 6.8 — In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media
CVE-2020-4048medium · CVSS 5.7 — In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted
CVE-2020-4049low · CVSS 2.4 — In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript
CVE-2020-4050low · CVSS 3.5 — In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It
CVE-2020-25286medium · CVSS 5.3 — In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments e
CVE-2020-28032critical · CVSS 9.8 — WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CVE-2020-28033high · CVSS 7.5 — WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
CVE-2020-28034medium · CVSS 6.1 — WordPress before 5.5.2 allows XSS associated with global variables.
CVE-2020-28035critical · CVSS 9.8 — WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
CVE-2020-28036critical · CVSS 9.8 — wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
CVE-2020-28037critical · CVSS 9.8 — is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which
CVE-2020-28038medium · CVSS 6.1 — WordPress before 5.5.2 allows stored XSS via post slugs.
CVE-2020-28039critical · CVSS 9.1 — is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine wh
CVE-2020-28040medium · CVSS 4.3 — WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
CVE-2021-29450medium · CVSS 6.5 — Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts a
CVE-2020-36326critical · CVSS 9.8 — PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is simi
CVE-2021-44223high · CVSS 8.1 — WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via
CVE-2022-21661high · CVSS 8.0 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitizatio
CVE-2022-21662high · CVSS 8.0 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticate
CVE-2022-21663medium · CVSS 6.6 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with
CVE-2022-21664high · CVSS 7.4 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanit