Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14541-14560 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-2189 - Wp Video Lightbox Plugin

The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Wp Video Lightbox

CVE-2022-2189

MEDIUM CVSS 6.1 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2115 - Popup Anything Plugin

The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting

PLUGIN Popup Anything

CVE-2022-2115

MEDIUM CVSS 6.1 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2072 - Name Directory Plugin

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

PLUGIN Name Directory

CVE-2022-2072

MEDIUM CVSS 6.1 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2071 - Name Directory Plugin

The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.

PLUGIN Name Directory

CVE-2022-2071

MEDIUM CVSS 6.1 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-0899 - Header Footer Code Manager Plugin

The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Header Footer Code Manager

CVE-2022-0899

MEDIUM CVSS 6.1 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2299 - Allow Svg Files Plugin

The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

PLUGIN Allow Svg Files

CVE-2022-2299

MEDIUM CVSS 5.4 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-0594 - Related Posts Plugin

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

PLUGIN Related Posts

CVE-2022-0594

MEDIUM CVSS 5.3 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2341 - Simple Page Transition Plugin

The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Simple Page Transition

CVE-2022-2341

MEDIUM CVSS 4.8 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2340 - W Dalil Plugin

The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN W Dalil

CVE-2022-2340

MEDIUM CVSS 4.8 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-2239 - Before 2 Plugin

The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2022-2239

MEDIUM CVSS 4.8 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2022-34853 - Team Plugin

Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin

PLUGIN Team

CVE-2022-34853

MEDIUM CVSS 4.1 2022-07-22
Threat Entry Updated 2024-11-21

CVE-2022-34650 - Team Plugin

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin

PLUGIN Team

CVE-2022-34650

MEDIUM CVSS 4.1 2022-07-22
Scroll to top