Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14261-14280 of 16313 records
Threat Entry Updated 2025-06-05

CVE-2022-2669 - Wp Taxonomy Import Plugin

The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Wp Taxonomy Import

CVE-2022-2669

MEDIUM CVSS 6.1 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2655 - Classified Listing Pro Plugin

The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Classified Listing Pro

CVE-2022-2655

MEDIUM CVSS 6.1 2022-09-16
Threat Entry Updated 2025-06-05

CVE-2022-2654 - Classified Listing Plugin

The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting

PLUGIN Classified Listing

CVE-2022-2654

MEDIUM CVSS 6.1 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2737 - Before 2 Plugin

The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 2

CVE-2022-2737

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2635 - Before 3 Plugin

The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 3

CVE-2022-2635

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2575 - Wbw Currency Switcher For Woocommerce Plugin

The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wbw Currency Switcher For Woocommerce

CVE-2022-2575

MEDIUM CVSS 4.8 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-2351 - Before 2 Plugin

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-2351

MEDIUM CVSS 4.8 2022-09-16
Scroll to top