Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2021-36827 - Ninja Forms Plugin
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin
CVE-2021-36827
CVE-2022-32280 - Xo Slider Plugin
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Xakuro's XO Slider plugin
CVE-2022-32280
CVE-2022-29452 - Export All Urls Plugin
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin
CVE-2022-29452
CVE-2022-28612 - Custom Popup Builder Plugin
Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin
CVE-2022-28612
CVE-2021-36891 - Photo Gallery Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin
CVE-2021-36891
CVE-2022-29450 - Admin Management Xtended Plugin
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin
CVE-2022-29450
CVE-2022-29443 - Hotel Booking Plugin
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin
CVE-2022-29443
CVE-2022-29453 - Api Key For Google Maps Plugin
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin
CVE-2022-29453
CVE-2022-29442 - Private Messages Plugin
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress
CVE-2022-29442
CVE-2022-29440 - Promotion Slider Plugin
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion Slider plugin
CVE-2022-29440
CVE-2022-29439 - Image Slider By Nextcode Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin
CVE-2022-29439
CVE-2022-29437 - Image Slider By Nextcode Plugin
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin
CVE-2022-29437
CVE-2022-29438 - Image Slider By Nextcode Plugin
Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCode plugin
CVE-2022-29438
CVE-2022-29441 - Private Messages Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin
CVE-2022-29441
CVE-2022-29406 - Wp Team Manager Plugin
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWebLab's WordPress Team Manager plugin
CVE-2022-29406
CVE-2022-27859 - Nd Travel Plugin
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin
CVE-2022-27859
CVE-2021-36901 - Age Gate Plugin
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker's Age Gate plugin
CVE-2021-36901
CVE-2022-1768 - Rsvpmaker Plugin
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.
CVE-2022-1768
CVE-2022-1969 - Mobile Browser Color Select Plugin
The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the admin_update_data() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2022-1969
CVE-2022-1749 - Find Any Think Plugin
The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.
CVE-2022-1749
