Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 301-320 of 472 records
Threat Entry Updated 2024-11-21

CVE-2022-2383 - Before 3 Plugin

The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2022-2383

MEDIUM CVSS 6.1 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2172 - Before 3 Plugin

The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.

PLUGIN Before 3

CVE-2022-2172

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2386 - Before 3 Plugin

The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2022-2386

MEDIUM CVSS 6.1 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2173 - Before 3 Plugin

The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2022-2173

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2025-03-21

CVE-2022-2168 - Before 3 Plugin

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2022-2168

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2118 - Before 3 Plugin

The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2022-2118

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2091 - Before 3 Plugin

The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.

PLUGIN Before 3

CVE-2022-2091

MEDIUM CVSS 6.5 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1474 - Before 3 Plugin

The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2022-1474

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2268 - Before 3 Plugin

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

PLUGIN Before 3

CVE-2022-2268

HIGH CVSS 7.2 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2021-25066 - Before 3 Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2021-25066

MEDIUM CVSS 4.8 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2021-25056 - Before 3 Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2021-25056

MEDIUM CVSS 4.8 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-1903 - Before 3 Plugin

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

PLUGIN Before 3

CVE-2022-1903

HIGH CVSS 8.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1964 - Before 3 Plugin

The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

PLUGIN Before 3

CVE-2022-1964

MEDIUM CVSS 5.4 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1990 - Before 3 Plugin

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

PLUGIN Before 3

CVE-2022-1990

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1627 - Before 3 Plugin

The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Before 3

CVE-2022-1627

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1709 - Before 3 Plugin

The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack

PLUGIN Before 3

CVE-2022-1709

MEDIUM CVSS 4.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1556 - Before 3 Plugin

The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

PLUGIN Before 3

CVE-2022-1556

CRITICAL CVSS 9.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1009 - Before 3 Plugin

The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker would need an admin to upload a malicious configuration file

PLUGIN Before 3

CVE-2022-1009

MEDIUM CVSS 6.1 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1560 - Before 3 Plugin

The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link

PLUGIN Before 3

CVE-2022-1560

MEDIUM CVSS 6.5 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1386 - Before 3 Plugin

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

PLUGIN Before 3

CVE-2022-1386

CRITICAL CVSS 9.8 2022-05-16
Scroll to top