Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14641-14660 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1995 - Malware Scanner Plugin

The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

PLUGIN Malware Scanner

CVE-2022-1995

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1994 - Whatsapp And Google Authenticator Plugin

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Whatsapp And Google Authenticator

CVE-2022-1994

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1990 - Nested Pages Plugin

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

PLUGIN Nested Pages

CVE-2022-1990

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1971 - Nextcellent Gallery Plugin

The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Nextcellent Gallery

CVE-2022-1971

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1960 - Mycss Plugin

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Mycss

CVE-2022-1960

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1914 - Clean Contact Plugin

The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well

PLUGIN Clean Contact

CVE-2022-1914

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1913 - Add Post Url Plugin

The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

PLUGIN Add Post Url

CVE-2022-1913

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1885 - Cimy Header Image Rotator Plugin

The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Cimy Header Image Rotator

CVE-2022-1885

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1574 - Html2wp Plugin

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

PLUGIN Html2wp

CVE-2022-1574

CRITICAL CVSS 9.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1572 - Html2wp Plugin

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

PLUGIN Html2wp

CVE-2022-1572

HIGH CVSS 8.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1843 - Mailpress Plugin

The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks

PLUGIN Mailpress

CVE-2022-1843

MEDIUM CVSS 6.5 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1593 - Site Offline Or Coming Soon Plugin

The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF attack

PLUGIN Site Offline Or Coming Soon

CVE-2022-1593

MEDIUM CVSS 6.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1776 - Optins And Lead Generation Plugin

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Optins And Lead Generation

CVE-2022-1776

MEDIUM CVSS 5.4 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1327 - Image Gallery Plugin

The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Image Gallery

CVE-2022-1327

MEDIUM CVSS 4.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1847 - Rotating Posts Plugin

The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Rotating Posts

CVE-2022-1847

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1846 - Tiny Contact Form Plugin

The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Tiny Contact Form

CVE-2022-1846

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1845 - Wp Post Styling Plugin

The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attackers to make a logged in admin delete plugin's data, update the settings, add new entries and more via CSRF attacks

PLUGIN Wp Post Styling

CVE-2022-1845

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1844 - Wp Sentry Plugin

The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

PLUGIN Wp Sentry

CVE-2022-1844

MEDIUM CVSS 4.3 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1842 - Openbook Book Data Plugin

The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

PLUGIN Openbook Book Data

CVE-2022-1842

MEDIUM CVSS 4.3 2022-06-27
Scroll to top