Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Robert Abela

Researcher fromNetsparker
#22116of 53,633
10.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2016-4040
6.1
2016-05-22
WordPress · Wordpress · CVE-2015-8834
**Name of the Vulnerable Software and Affected Versions** WordPress versions prior to 4.2.2 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored due to limitations on the MySQL TEXT data type. **Recommendations** For versions prior to 4.2.2, update to version 4.2.2 or later to resolve the issue.
PT-2015-6226
4.3
2015-06-17
Automattic · Wordpress · CVE-2015-3429
**Name of the Vulnerable Software and Affected Versions** Genericons versions prior to 3.3.1 WordPress versions prior to 4.2.2 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a fragment identifier. This affects the example.html file in Genericons, which is used in WordPress. **Recommendations** For Genericons versions prior to 3.3.1, update to version 3.3.1 or later. For WordPress versions prior to 4.2.2, update to version 4.2.2 or later.