Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14241-14260 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-3141 - Translate Multilingual Sites Plugin

The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.

PLUGIN Translate Multilingual Sites

CVE-2022-3141

HIGH CVSS 8.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2958 - Before 3 Plugin

The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

PLUGIN Before 3

CVE-2022-2958

HIGH CVSS 8.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-3036 - Gettext Override Translations Plugin

The Gettext override translations WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Gettext Override Translations

CVE-2022-3036

MEDIUM CVSS 4.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-3021 - Slickr Flickr Plugin

The Slickr Flickr WordPress plugin through 2.8.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Slickr Flickr

CVE-2022-3021

MEDIUM CVSS 4.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2754 - Ketchup Restaurant Reservations Plugin

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

PLUGIN Ketchup Restaurant Reservations

CVE-2022-2754

CRITICAL CVSS 9.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2753 - Ketchup Restaurant Reservations Plugin

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made

PLUGIN Ketchup Restaurant Reservations

CVE-2022-2753

MEDIUM CVSS 6.1 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2710 - Scroll To Top Plugin

The Scroll To Top WordPress plugin before 1.4.1 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Scroll To Top

CVE-2022-2710

MEDIUM CVSS 4.8 2022-09-19
Threat Entry Updated 2026-02-10

CVE-2022-2709 - Float To Top Button Plugin

The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Float To Top Button

CVE-2022-2709

MEDIUM CVSS 4.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2567 - Form Builder Cp Plugin

The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Form Builder Cp

CVE-2022-2567

MEDIUM CVSS 4.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-1591 - Wordpress Ping Optimizer Plugin

The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Wordpress Ping Optimizer

CVE-2022-1591

MEDIUM CVSS 4.3 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-1580 - Site Offline Or Coming Soon Or Maintenance Mode Plugin

The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.

PLUGIN Site Offline Or Coming Soon Or Maintenance Mode

CVE-2022-1580

MEDIUM CVSS 4.3 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2877 - Before 7 Plugin

The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

PLUGIN Before 7

CVE-2022-2877

MEDIUM CVSS 5.3 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2863 - Before 0 Plugin

The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack

PLUGIN Before 0

CVE-2022-2863

MEDIUM CVSS 4.9 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2887 - Wp Server Health Stats Plugin

The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wp Server Health Stats

CVE-2022-2887

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2799 - Affiliates Manager Plugin

The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Affiliates Manager

CVE-2022-2799

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2025-06-03

CVE-2022-2913 - Login No Captcha Recaptcha Plugin

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

PLUGIN Login No Captcha Recaptcha

CVE-2022-2913

MEDIUM CVSS 4.3 2022-09-16
Threat Entry Updated 2025-06-03

CVE-2022-2912 - Through 1 Plugin

The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).

PLUGIN Through 1

CVE-2022-2912

MEDIUM CVSS 4.3 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-1194 - Mobile Events Manager Plugin

The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.

PLUGIN Mobile Events Manager

CVE-2022-1194

HIGH CVSS 8.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2798 - Affiliates Manager Plugin

The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data

PLUGIN Affiliates Manager

CVE-2022-2798

HIGH CVSS 8.0 2022-09-16
Scroll to top