VDB
GCVE-VVD-MAGEIA-2014-493
GCVE-VVD-MAGEIA-2014-493
Advisory Published
XSS in wptexturize() via comments or posts, exploitable for unauthenticated users (CVE-2014-9031).
XSS in media playlists (CVE-2014-9032).
CSRF in the password reset process (CVE-2014-9033).
Denial of service for giant passwords. The phpass library by Solar Designer
was used in both projects without setting a maximum password length, which
can lead to CPU exhaustion upon hashing (CVE-2014-9034).
XSS in Press This (CVE-2014-9035).
XSS in HTML filtering of CSS in posts (CVE-2014-9036).
Hash comparison vulnerability in old-style MD5-stored passwords
(CVE-2014-9037).
SSRF: Safe HTTP requests did not sufficiently block the loopback IP address
space (CVE-2014-9038).
Previously an email address change would not invalidate a previous password
reset email (CVE-2014-9039).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | wordpress | 0 (affected), 3.9.3-1.mga4 (unaffected) | — |
| Mageia | wordpress | 0 (affected), 3.9.3-1.mga3 (unaffected) | — |
Browse GCVE Records
74,108 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.