Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3241-3260 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2022-0760 - Changeset Plugin

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

PLUGIN Changeset

CVE-2022-0760

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0747 - Changeset Plugin

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

PLUGIN Changeset

CVE-2022-0747

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0739 - Changeset Plugin

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

PLUGIN Changeset

CVE-2022-0739

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0694 - Changeset Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Changeset

CVE-2022-0694

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0640 - Changeset Plugin

The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Changeset

CVE-2022-0640

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0628 - Changeset Plugin

The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Changeset

CVE-2022-0628

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0601 - Changeset Plugin

The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Changeset

CVE-2022-0601

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0684 - Changeset Plugin

The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2022-0684

MEDIUM CVSS 4.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0254 - Changeset Plugin

The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

PLUGIN Changeset

CVE-2022-0254

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0169 - Changeset Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Changeset

CVE-2022-0169

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0478 - Changeset Plugin

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks

PLUGIN Changeset

CVE-2022-0478

HIGH CVSS 8.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0399 - Changeset Plugin

The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0399

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0248 - Changeset Plugin

The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission

PLUGIN Changeset

CVE-2022-0248

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0161 - Changeset Plugin

The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2022-0161

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0147 - Changeset Plugin

The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2022-0147

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-25026 - Changeset Plugin

The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2021-25026

MEDIUM CVSS 5.5 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0441 - Changeset Plugin

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

PLUGIN Changeset

CVE-2022-0441

CRITICAL CVSS 9.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0420 - Changeset Plugin

The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

PLUGIN Changeset

CVE-2022-0420

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0422 - Changeset Plugin

The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2022-0422

MEDIUM CVSS 6.1 2022-03-07
Scroll to top