Vulnerability Name CVE Severity
Web Server Cache Poisoning (CMS Made Simple) v1.x CVE-2016-2784
Web Server Cache Poisoning (CMS Made Simple) v2.x CVE-2016-2784
Web server default welcome page
Werkzeug WSGI Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-25577) CVE-2023-25577
Werkzeug WSGI Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-49767) CVE-2024-49767
Werkzeug WSGI Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-34069) CVE-2024-34069
Werkzeug WSGI CVE-2023-23934 Vulnerability (CVE-2023-23934) CVE-2023-23934
Werkzeug WSGI Improper Handling of Windows Device Names Vulnerability (CVE-2025-66221) CVE-2025-66221
Werkzeug WSGI Improper Handling of Windows Device Names Vulnerability (CVE-2026-21860) CVE-2026-21860
Werkzeug WSGI Improper Handling of Windows Device Names Vulnerability (CVE-2026-27199) CVE-2026-27199
Werkzeug WSGI Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-14322) CVE-2019-14322
Werkzeug WSGI Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2024-49766) CVE-2024-49766
Werkzeug WSGI Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-10516) CVE-2016-10516
Werkzeug WSGI Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2022-29361) CVE-2022-29361
Werkzeug WSGI Insufficient Entropy Vulnerability (CVE-2019-14806) CVE-2019-14806
Werkzeug WSGI Out-of-bounds Write Vulnerability (CVE-2023-46136) CVE-2023-46136
Werkzeug WSGI URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-28724) CVE-2020-28724
Whoops error handler component detected
Wildcard Detected in Domain Portion of Content Security Policy (CSP) Directive
Wildcard Detected in Port Portion of Content Security Policy (CSP) Directive
Wildcard Detected in Scheme Portion of Content Security Policy (CSP) Directive
WildFly Application Server Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0793) CVE-2016-0793
WildFly Application Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-1047) CVE-2018-1047
WildFly Application Server Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') Vulnerability (CVE-2016-4993) CVE-2016-4993
WildFly Application Server Uncontrolled Resource Consumption Vulnerability (CVE-2016-9589) CVE-2016-9589
Wing FTP Anonymous access
Wing FTP Server RCE (CVE-2025-47812) CVE-2025-47812
WooCommerce Payments Authentication Bypass and Privilege Escalation CVE-2023-28121
WooFramework shortcode exploit
WordPress 'admin-ajax.php' SQL Injection Vulnerability (2.1.3) CVE-2007-2821
WordPress 'blog.header.php' Multiple SQL Injection Vulnerabilities (0.6.2 - 0.71)
WordPress 'cat' Parameter SQL Injection Vulnerability (1.5 - 1.5.1.1) CVE-2005-1810
WordPress 'comment_post_ID' Parameter SQL Injection Vulnerability (3.0.4)
WordPress 'edit.php' Cross-Site Scripting Vulnerability (1.5)
WordPress 'get_edit_post_link()' and 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities (0.6.2 - 2.6) CVE-2008-3747
WordPress 'index.php' Cross-Site Scripting Vulnerability (1.5)
WordPress 'paged' Parameter SQL Injection Vulnerability (2.0.2 - 2.0.5) CVE-2006-3389
WordPress 'post.php' Cross-Site Scripting Vulnerability (1.5)
WordPress 'press-this.php' Multiple Cross-Site Scripting Vulnerabilities (2.0 - 2.5.1) CVE-2008-3233
WordPress 'press-this.php' Remote Security Bypass Vulnerability (0.7 - 3.1.1) CVE-2011-5270
WordPress 'swfupload.swf' Cross-Site Scripting Vulnerability (2.5 - 3.3.1) CVE-2012-3414
WordPress 'templates.php' Cross-Site Scripting Vulnerability (0.6.2 - 2.1) CVE-2007-1049
WordPress 'wp-admin/admin.php' Module Configuration Security Bypass Vulnerability (0.6.2 - 2.8) CVE-2009-2334
WordPress 'wp-admin/options.php' Remote Code Execution Vulnerability (0.6.2 - 2.3.2) CVE-2008-5695
WordPress 'wp-db.php' Character Set SQL Injection Vulnerability (2.0 - 2.3.1) CVE-2007-6318
WordPress 'wp-login.php' HTTP Response Splitting Vulnerability (1.2) CVE-2004-1584
WordPress 'wp-register.php' Multiple Cross-Site Scripting Vulnerabilities (2.0 - 2.0.1) CVE-2007-5105 CVE-2007-5106
WordPress 'wp-trackback.php' SQL Injection Vulnerability (1.5) CVE-2005-1687
WordPress 'xmlrpc.php' Remote Security Bypass Vulnerability (3.0.1 - 3.0.2) CVE-2010-5106
WordPress 0.7 Posts SQL Injection Vulnerability (0.7) CVE-2003-1598
WordPress 1.5.1.2 Multiple Vulnerabilities (1.0 - 1.5.1.2) CVE-2005-2107 CVE-2005-2108 CVE-2005-2109 CVE-2005-2110
WordPress 2.0.1 Denial of Service Vulnerability (0.6.2 - 2.0.1)
WordPress 2.0.2 Username Remote PHP Code Injection Vulnerability (0.6.2 - 2.0.2) CVE-2006-2667 CVE-2006-2702
WordPress 2.0.3 Multiple Unspecified Security Vulnerabilities (2.0 - 2.0.3) CVE-2006-4028
WordPress 2.0.4 Multiple Security Vulnerabilities (2.0.4) CVE-2006-5705 CVE-2006-6016 CVE-2006-6017
WordPress 2.0.5 Charset Decoding SQL Injection Vulnerability (0.6.2 - 2.0.5) CVE-2007-0107
WordPress 2.0.5 Cross-Site Scripting Vulnerability (0.6.2 - 2.0.5) CVE-2006-6808
WordPress 2.0.5 Invalid CSRF Token Cross-Site Scripting Vulnerability (0.6.2 - 2.0.5) CVE-2007-0106
WordPress 2.0.6 'Zend_Hash_Del_Key_Or_Index' SQL Injection Vulnerability (0.6.2 - 2.0.6) CVE-2007-0233
WordPress 2.0.9 Multiple Vulnerabilities (2.0 - 2.0.9) CVE-2007-1622 CVE-2007-1893 CVE-2007-1894 CVE-2007-1897
WordPress 2.1.1 Command Execution Backdoor Vulnerability (2.1.1) CVE-2007-1277
WordPress 2.1.1 Cross-Site Scripting Vulnerability (2.1.1) CVE-2007-1244
WordPress 2.1.2 Multiple Vulnerabilities (2.1 - 2.1.2) CVE-2007-1622 CVE-2007-1893 CVE-2007-1894 CVE-2007-1897
WordPress 2.2 Cross-Site Scripting Vulnerability (2.2) CVE-2007-3238
WordPress 2.2 Multiple Vulnerabilities (2.2) CVE-2007-3140 CVE-2007-3238 CVE-2007-3543
WordPress 2.2.1 Multiple Vulnerabilities (2.2.1) CVE-2007-3639 CVE-2007-4139 CVE-2007-4153 CVE-2007-4154
WordPress 2.2.2 Multiple Vulnerabilities (2.2 - 2.2.2) CVE-2007-4893 CVE-2007-4894 CVE-2008-2146
WordPress 2.3 Cross-Site Scripting Vulnerability (2.3) CVE-2007-5710
WordPress 2.3.1 Unauthorized Post Access Vulnerability (2.3.1)
WordPress 2.3.2 Post Edit Unauthorized Access Vulnerability (0.7 - 2.3.2) CVE-2008-0664
WordPress 2.3.3 Directory Traversal Vulnerability (0.6.2 - 2.3.3) CVE-2008-4769
WordPress 2.5 Cookie Integrity Protection Unauthorized Access Vulnerability (0.6.2 - 2.5) CVE-2008-1930
WordPress 2.5 Cross-Site Scripting Vulnerability (2.5) CVE-2008-2068
WordPress 2.6.1 Lost Password SQL Column Truncation Unauthorized Access Vulnerability (0.71 - 2.6.1) CVE-2008-4106 CVE-2008-4107
WordPress 2.6.2 Remote Code Execution Vulnerability (0.70 - 2.6.2) CVE-2008-4796