Total vulnerabilities in the database
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
Software | From | Fixed in |
---|---|---|
WordPress / wordpress | - | 4.9.5 |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |