Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14621-14640 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1220 - Before 4 Plugin

The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 4

CVE-2022-1220

MEDIUM CVSS 6.1 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1938 - Awin Data Feed Plugin

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings

PLUGIN Awin Data Feed

CVE-2022-1938

MEDIUM CVSS 5.4 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1757 - Before 2 Plugin

The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues

PLUGIN Before 2

CVE-2022-1757

MEDIUM CVSS 5.4 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1626 - Sharebar Plugin

The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them

PLUGIN Sharebar

CVE-2022-1626

MEDIUM CVSS 5.4 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1894 - Popup Builder Plugin

The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed

PLUGIN Popup Builder

CVE-2022-1894

MEDIUM CVSS 4.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-2268 - Import Any Xml Or Csv File To Plugin

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

PLUGIN Import Any Xml Or Csv File To

CVE-2022-2268

HIGH CVSS 7.2 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-1967 - Wp Championship Plugin

The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

PLUGIN Wp Championship

CVE-2022-1967

MEDIUM CVSS 6.5 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-1946 - Before 2 Plugin

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2022-1946

MEDIUM CVSS 6.1 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-1301 - Wp Contact Slider Plugin

The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Wp Contact Slider

CVE-2022-1301

MEDIUM CVSS 4.8 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2021-25066 - Ninja Forms Contact Form Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Ninja Forms Contact Form

CVE-2021-25066

MEDIUM CVSS 4.8 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2021-25056 - Ninja Forms Contact Form Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Ninja Forms Contact Form

CVE-2021-25056

MEDIUM CVSS 4.8 2022-07-04
Threat Entry Updated 2024-11-21

CVE-2022-1953 - Product Configurator For Woocommerce Plugin

The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first

PLUGIN Product Configurator For Woocommerce

CVE-2022-1953

CRITICAL CVSS 9.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1903 - Before 3 Plugin

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

PLUGIN Before 3

CVE-2022-1903

HIGH CVSS 8.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1977 - Before 6 Plugin

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

PLUGIN Before 6

CVE-2022-1977

HIGH CVSS 7.2 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1916 - Professional Products Tables For Woocommerce Store Plugin

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting

PLUGIN Professional Products Tables For Woocommerce Store

CVE-2022-1916

MEDIUM CVSS 6.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1904 - Pricing Tables Plugin

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting

PLUGIN Pricing Tables

CVE-2022-1904

MEDIUM CVSS 6.1 2022-06-27
Threat Entry Updated 2025-01-16

CVE-2022-2041 - Before 2 Plugin

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2022-2041

MEDIUM CVSS 5.4 2022-06-27
Threat Entry Updated 2025-01-16

CVE-2022-2040 - Before 2 Plugin

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2022-2040

MEDIUM CVSS 5.4 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1964 - Easy Svg Support Plugin

The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

PLUGIN Easy Svg Support

CVE-2022-1964

MEDIUM CVSS 5.4 2022-06-27
Scroll to top