Cryptopsyby CloudTrace

Image reports › wordpress

wordpress — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/wordpress · Debian GNU/Linux 13 (trixie)

Latest: wordpress:latest · checked 2026-09-25

Not FIPS-ready

No. wordpress:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 278 known vulnerabilities

278 known vulnerabilities in 65 packages (13 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
highCVE-2021-3575libopenjp2-7 2.5.3-2.1~deb13u2no fix yetA heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
highCVE-2019-19449linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).
highCVE-2019-19814linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
highCVE-2021-3847linux-libc-dev 6.12.107-1no fix yetAn unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.
highCVE-2024-21803linux-libc-dev 6.12.107-1no fix yetUse After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C.
highCVE-2024-26461libgssapi-krb5-2 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libk5crypto3 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5-3 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5support0 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-25062libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix yetAn issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
highCVE-2024-41013linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2024-41014linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2021-3864linux-libc-dev 6.12.107-1no fix yetA flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a resul

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyC 2782026-09-25Full report