Wp 6.7.1 #2223
Wp 6.7.1 #2223
15 new alerts including 15 medium severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 15 medium
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check warning on line 204 in wp/wp-admin/js/edit-comments.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 433 in wp/wp-admin/js/edit-comments.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 436 in wp/wp-admin/js/edit-comments.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 443 in wp/wp-admin/js/edit-comments.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check failure on line 1186 in wp/wp-admin/js/edit-comments.js
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check failure on line 346 in wp/wp-admin/js/editor.js
Code scanning / CodeQL
Useless regular-expression character escape High
.
Check failure on line 346 in wp/wp-admin/js/editor.js
Code scanning / CodeQL
Useless regular-expression character escape High
.
Check warning on line 220 in wp/wp-admin/js/inline-edit-post.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check failure on line 515 in wp/wp-admin/js/inline-edit-post.js
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check warning on line 1023 in wp/wp-admin/js/nav-menu.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 1426 in wp/wp-admin/js/nav-menu.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check failure on line 2375 in wp/wp-admin/js/updates.js
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check failure on line 385 in wp/wp-admin/js/user-profile.js
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check warning on line 433 in wp/wp-admin/js/user-profile.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check failure on line 34645 in wp/wp-includes/js/dist/block-editor.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 16898 in wp/wp-includes/js/dist/block-library.js
Code scanning / CodeQL
Incomplete regular expression for hostnames High
Check failure on line 16990 in wp/wp-includes/js/dist/block-library.js
Code scanning / CodeQL
Incomplete regular expression for hostnames High
Check failure on line 17033 in wp/wp-includes/js/dist/block-library.js
Code scanning / CodeQL
Incomplete regular expression for hostnames High
Check failure on line 5708 in wp/wp-includes/js/dist/blocks.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 32662 in wp/wp-includes/js/dist/components.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 1092 in wp/wp-includes/js/dist/format-library.js
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check failure on line 97 in wp/wp-includes/js/tinymce/plugins/wplink/plugin.js
Code scanning / CodeQL
Inefficient regular expression High
Check failure on line 258 in wp/wp-includes/js/tinymce/plugins/wplink/plugin.js
Code scanning / CodeQL
Incomplete URL scheme check High
Check failure on line 336 in wp/wp-includes/js/tinymce/plugins/wplink/plugin.js
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check failure on line 3 in wp/wp-includes/js/tinymce/wp-tinymce.js
Code scanning / CodeQL
Incomplete string escaping or encoding High