Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14581-14600 of 16358 records
Threat Entry Updated 2025-03-21

CVE-2022-2101 - Download Manager Plugin

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page.

PLUGIN Download Manager

CVE-2022-2101

MEDIUM CVSS 6.4 2022-07-18
Threat Entry Updated 2024-11-21

CVE-2022-2187 - Contact Form 7 Captcha Plugin

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Contact Form 7 Captcha

CVE-2022-2187

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2173 - Advanced Database Cleaner Plugin

The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting

PLUGIN Advanced Database Cleaner

CVE-2022-2173

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2025-03-21

CVE-2022-2168 - Download Manager Plugin

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

PLUGIN Download Manager

CVE-2022-2168

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2222 - Download Monitor Plugin

The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

PLUGIN Download Monitor

CVE-2022-2222

MEDIUM CVSS 4.9 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2194 - Accept Stripe Payments Plugin

The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Accept Stripe Payments

CVE-2022-2194

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2186 - Simple Post Notes Plugin

The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Simple Post Notes

CVE-2022-2186

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2169 - Loading Page With Loading Screen Plugin

The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Loading Page With Loading Screen

CVE-2022-2169

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2151 - Best Contact Management Software Plugin

The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Best Contact Management Software

CVE-2022-2151

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2149 - Very Simple Breadcrumb Plugin

The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Very Simple Breadcrumb

CVE-2022-2149

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2148 - Linkedin Company Updates Plugin

The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Linkedin Company Updates

CVE-2022-2148

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-1672 - Insights From Google Pagespeed Plugin

The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

PLUGIN Insights From Google Pagespeed

CVE-2022-1672

HIGH CVSS 8.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2021-24655 - Wp User Manager Plugin

The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.

PLUGIN Wp User Manager

CVE-2021-24655

HIGH CVSS 7.5 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2146 - Import Csv Files Plugin

The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting

PLUGIN Import Csv Files

CVE-2022-2146

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2090 - Discount Rules For Woocommerce Plugin

The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting

PLUGIN Discount Rules For Woocommerce

CVE-2022-2090

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-1933 - Before 5 Plugin

The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

PLUGIN Before 5

CVE-2022-1933

MEDIUM CVSS 6.1 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2133 - Oauth Single Sign On Plugin

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

PLUGIN Oauth Single Sign On

CVE-2022-2133

MEDIUM CVSS 5.3 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2118 - Before 3 Plugin

The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2022-2118

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2114 - Data Tables Generator By Supsystic Plugin

The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Data Tables Generator By Supsystic

CVE-2022-2114

MEDIUM CVSS 4.8 2022-07-17
Threat Entry Updated 2024-11-21

CVE-2022-2100 - Page Generator Plugin

The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Page Generator

CVE-2022-2100

MEDIUM CVSS 4.8 2022-07-17
Scroll to top