Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14161-14180 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-2891 - Before 2 Plugin

The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.

PLUGIN Before 2

CVE-2022-2891

MEDIUM CVSS 5.9 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2350 - Disable User Login Plugin

The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.

PLUGIN Disable User Login

CVE-2022-2350

MEDIUM CVSS 5.3 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2981 - Download Monitor Plugin

The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

PLUGIN Download Monitor

CVE-2022-2981

MEDIUM CVSS 4.9 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2554 - Enable Media Replace Plugin

The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

PLUGIN Enable Media Replace

CVE-2022-2554

MEDIUM CVSS 4.9 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2823 - And Carousel By Metaslider Plugin

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN And Carousel By Metaslider

CVE-2022-2823

MEDIUM CVSS 4.8 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2629 - Top Bar Plugin

The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in frontend pages, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Top Bar

CVE-2022-2629

MEDIUM CVSS 4.8 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-2448 - Before 0 Plugin

The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Before 0

CVE-2022-2448

MEDIUM CVSS 4.8 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2021-25044 - Cryptocurrency Pricing List And Ticker Plugin

The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading to a Reflected Cross-Site Scripting issue

PLUGIN Cryptocurrency Pricing List And Ticker

CVE-2021-25044

MEDIUM CVSS 6.1 2022-10-10
Threat Entry Updated 2024-11-21

CVE-2022-3132 - Before 1 Plugin

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2022-3132

MEDIUM CVSS 4.8 2022-10-03
Threat Entry Updated 2024-11-21

CVE-2022-3128 - Donation Thermometer Plugin

The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Donation Thermometer

CVE-2022-3128

MEDIUM CVSS 4.8 2022-10-03
Threat Entry Updated 2024-11-21

CVE-2022-3125 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

PLUGIN Frontend File Manager

CVE-2022-3125

HIGH CVSS 8.8 2022-10-03
Threat Entry Updated 2024-11-21

CVE-2022-3124 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server

PLUGIN Frontend File Manager

CVE-2022-3124

MEDIUM CVSS 5.3 2022-10-03
Threat Entry Updated 2024-11-21

CVE-2022-2839 - Zephyr Project Manager Plugin

The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.

PLUGIN Zephyr Project Manager

CVE-2022-2839

MEDIUM CVSS 5.4 2022-10-03
Threat Entry Updated 2024-11-21

CVE-2022-2763 - Wp Socializer Plugin

The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Socializer

CVE-2022-2763

MEDIUM CVSS 4.8 2022-10-03
Threat Entry Updated 2024-11-21

CVE-2022-2628 - Dsgvo All In One For Wp Plugin

The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Dsgvo All In One For Wp

CVE-2022-2628

MEDIUM CVSS 4.8 2022-10-03
Scroll to top