Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14281-14300 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-3026 - Wp Users Exporter Plugin

The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like First Names that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

PLUGIN Wp Users Exporter

CVE-2022-3026

MEDIUM CVSS 6.5 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2936 - Image Hover Effects Ultimate Plugin

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to lower privileged…

PLUGIN Image Hover Effects Ultimate

CVE-2022-2936

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2024-11-21

CVE-2022-2935 - Image Hover Effects Ultimate Plugin

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to…

PLUGIN Image Hover Effects Ultimate

CVE-2022-2935

MEDIUM CVSS 6.4 2022-09-06
Threat Entry Updated 2025-05-05

CVE-2022-2941 - Wp Useronline Plugin

The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input, nor escape it on output. This makes it possible for authenticated attackers, with administrative privileges, to inject JavaScript code into the setting that will execute whenever a user accesses the injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp Useronline

CVE-2022-2941

MEDIUM CVSS 5.5 2022-09-06
Scroll to top