Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14421-14440 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2021-24911 - Transposh Wordpress Translation Plugin

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin "Who can translate ?" setting.

PLUGIN Transposh Wordpress Translation

CVE-2021-24911

MEDIUM CVSS 5.4 2022-08-22
Threat Entry Updated 2025-04-15

CVE-2022-2846 - Calendar Event Multi View Plugin

The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.

PLUGIN Calendar Event Multi View

CVE-2022-2846

MEDIUM CVSS 4.3 2022-08-16
Threat Entry Updated 2024-11-21

CVE-2022-2535 - Searchwp Live Ajax Search Plugin

The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

PLUGIN Searchwp Live Ajax Search

CVE-2022-2535

MEDIUM CVSS 5.3 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2384 - Digital Publications By Supsystic Plugin

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Digital Publications By Supsystic

CVE-2022-2384

MEDIUM CVSS 4.8 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2381 - E Unlocked Student Result Plugin

The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack

PLUGIN E Unlocked Student Result

CVE-2022-2381

HIGH CVSS 8.8 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2379 - Easy Student Results Plugin

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc

PLUGIN Easy Student Results

CVE-2022-2379

HIGH CVSS 7.5 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2354 - Wp Dbmanager Plugin

The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.

PLUGIN Wp Dbmanager

CVE-2022-2354

HIGH CVSS 7.2 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2378 - Easy Student Results Plugin

The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Easy Student Results

CVE-2022-2378

MEDIUM CVSS 6.1 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2180 - Greyd Suite Plugin

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

PLUGIN Greyd Suite

CVE-2022-2180

CRITICAL CVSS 9.8 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2152 - Duplicate Page And Post Plugin

The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Duplicate Page And Post

CVE-2022-2152

MEDIUM CVSS 4.8 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-2116 - Contact Form Db Plugin

The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

PLUGIN Contact Form Db

CVE-2022-2116

MEDIUM CVSS 6.1 2022-08-15
Threat Entry Updated 2025-09-03

CVE-2022-2460 - Before 7 Plugin

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

PLUGIN Before 7

CVE-2022-2460

CRITICAL CVSS 9.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2426 - Thinkific Uploader Plugin

The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks against other administrators.

PLUGIN Thinkific Uploader

CVE-2022-2426

MEDIUM CVSS 4.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2425 - Wp Ds Blog Map Plugin

The WP DS Blog Map WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Wp Ds Blog Map

CVE-2022-2425

MEDIUM CVSS 4.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2424 - Google Maps Anywhere Plugin

The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Google Maps Anywhere

CVE-2022-2424

MEDIUM CVSS 4.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2423 - Dw Promobar Plugin

The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Dw Promobar

CVE-2022-2423

MEDIUM CVSS 4.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2412 - Better Tag Cloud Plugin

The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Better Tag Cloud

CVE-2022-2412

MEDIUM CVSS 4.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2386 - Crowdsignal Dashboard Plugin

The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Crowdsignal Dashboard

CVE-2022-2386

MEDIUM CVSS 6.1 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2391 - Inspiro Pro Plugin

The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.

PLUGIN Inspiro Pro

CVE-2022-2391

MEDIUM CVSS 5.4 2022-08-08
Scroll to top