Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14121-14140 of 16313 records
Threat Entry Updated 2025-05-07

CVE-2022-3392 - Through 1 Plugin

The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Through 1

CVE-2022-3392

MEDIUM CVSS 4.8 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3391 - Retain Live Chat Plugin

The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Retain Live Chat

CVE-2022-3391

MEDIUM CVSS 4.8 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3350 - Contact Bank Plugin

The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Contact Bank

CVE-2022-3350

MEDIUM CVSS 4.8 2022-10-25
Threat Entry Updated 2025-05-07

CVE-2022-3246 - Before 6 Plugin

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers

PLUGIN Before 6

CVE-2022-3246

HIGH CVSS 8.8 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3302 - Firewall By Cleantalk Plugin

The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin

PLUGIN Firewall By Cleantalk

CVE-2022-3302

HIGH CVSS 7.2 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3300 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PLUGIN Form Maker By 10web

CVE-2022-3300

HIGH CVSS 7.2 2022-10-25
Threat Entry Updated 2025-05-09

CVE-2022-3247 - Before 6 Plugin

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks

PLUGIN Before 6

CVE-2022-3247

MEDIUM CVSS 6.5 2022-10-25
Threat Entry Updated 2025-05-07

CVE-2022-3097 - Plugin Lbstopattack

The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections.

PLUGIN Plugin Lbstopattack

CVE-2022-3097

MEDIUM CVSS 6.5 2022-10-25
Threat Entry Updated 2025-05-08

CVE-2022-2762 - Before 2 Plugin

The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack

PLUGIN Before 2

CVE-2022-2762

MEDIUM CVSS 6.5 2022-10-25
Threat Entry Updated 2024-11-21

CVE-2022-38104 - Accordions Or Faqs Plugin

Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions

PLUGIN Accordions Or Faqs

CVE-2022-38104

HIGH CVSS 7.2 2022-10-21
Threat Entry Updated 2025-05-14

CVE-2022-3243 - Before 6 Plugin

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

PLUGIN Before 6

CVE-2022-3243

HIGH CVSS 7.2 2022-10-17
Threat Entry Updated 2025-05-14

CVE-2022-3150 - Before 3 Plugin

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin

PLUGIN Before 3

CVE-2022-3150

HIGH CVSS 7.2 2022-10-17
Threat Entry Updated 2025-05-14

CVE-2022-3131 - Search Logger Plugin

The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

PLUGIN Search Logger

CVE-2022-3131

HIGH CVSS 7.2 2022-10-17
Threat Entry Updated 2025-05-13

CVE-2022-3082 - Miniorange Discord Integration Plugin

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

PLUGIN Miniorange Discord Integration

CVE-2022-3082

MEDIUM CVSS 6.5 2022-10-17
Threat Entry Updated 2025-05-14

CVE-2022-3149 - Wp Custom Cursors Plugin

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

PLUGIN Wp Custom Cursors

CVE-2022-3149

MEDIUM CVSS 6.1 2022-10-17
Threat Entry Updated 2025-05-14

CVE-2022-3206 - Before 3 Plugin

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

PLUGIN Before 3

CVE-2022-3206

MEDIUM CVSS 5.9 2022-10-17
Threat Entry Updated 2025-05-14

CVE-2022-3139 - Before 1 Plugin

The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 1

CVE-2022-3139

MEDIUM CVSS 4.8 2022-10-17
Scroll to top