Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 541-560 of 837 records
Threat Entry Updated 2024-11-21

CVE-2022-1091 - Before 1 Plugin

The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).

PLUGIN Before 1

CVE-2022-1091

MEDIUM CVSS 6.1 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1037 - Before 1 Plugin

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

PLUGIN Before 1

CVE-2022-1037

HIGH CVSS 7.2 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0879 - Before 1 Plugin

The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-0879

MEDIUM CVSS 6.1 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1001 - Before 1 Plugin

The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin to perform Cross-Site attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2022-1001

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1023 - Before 1 Plugin

The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file

PLUGIN Before 1

CVE-2022-1023

HIGH CVSS 7.2 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1006 - Before 1 Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks

PLUGIN Before 1

CVE-2022-1006

HIGH CVSS 7.2 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1007 - Before 1 Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-1007

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0471 - Before 1 Plugin

The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-0471

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0246 - Before 1 Plugin

The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the extraction process, existence of a file is checked. If the file exists, it is deleted without any security control by only considering the name of the extracted file. This behavior leads to "Zip Slip" vulnerability.

PLUGIN Before 1

CVE-2022-0246

MEDIUM CVSS 4.9 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0709 - Before 1 Plugin

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

PLUGIN Before 1

CVE-2022-0709

HIGH CVSS 7.5 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0864 - Before 1 Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

PLUGIN Before 1

CVE-2022-0864

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0837 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.

PLUGIN Before 1

CVE-2022-0837

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0825 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

PLUGIN Before 1

CVE-2022-0825

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0680 - Before 1 Plugin

The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configuration_tracker_enable option, which is then displayed in the admin panel without sanitisation and escaping, leading to a Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-0680

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0720 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

PLUGIN Before 1

CVE-2022-0720

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0595 - Before 1 Plugin

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-0595

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0739 - Before 1 Plugin

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

PLUGIN Before 1

CVE-2022-0739

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0694 - Before 1 Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Before 1

CVE-2022-0694

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0687 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

PLUGIN Before 1

CVE-2022-0687

HIGH CVSS 8.8 2022-03-21
Scroll to top