Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14781-14800 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1647 - Before 1 Plugin

The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2022-1647

MEDIUM CVSS 4.8 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1712 - Livesync Plugin

The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Livesync

CVE-2022-1712

MEDIUM CVSS 4.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1709 - Throws Spam Away Plugin

The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack

PLUGIN Throws Spam Away

CVE-2022-1709

MEDIUM CVSS 4.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1695 - Wp Simple Adsense Insertion Plugin

The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.

PLUGIN Wp Simple Adsense Insertion

CVE-2022-1695

MEDIUM CVSS 4.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1690 - Note Press Plugin

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

PLUGIN Note Press

CVE-2022-1690

LOW CVSS 2.7 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1689 - Note Press Plugin

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection

PLUGIN Note Press

CVE-2022-1689

LOW CVSS 2.7 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1688 - Note Press Plugin

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

PLUGIN Note Press

CVE-2022-1688

LOW CVSS 2.7 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1687 - Logo Slider Plugin

The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection

PLUGIN Logo Slider

CVE-2022-1687

LOW CVSS 2.7 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1686 - Five Minute Webshop Plugin

The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection

PLUGIN Five Minute Webshop

CVE-2022-1686

LOW CVSS 2.7 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1684 - Cube Slider Plugin

The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin

PLUGIN Cube Slider

CVE-2022-1684

LOW CVSS 2.7 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1570 - Files Download Delay Plugin

The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.

PLUGIN Files Download Delay

CVE-2022-1570

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1424 - Ask Me Plugin

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

PLUGIN Ask Me

CVE-2022-1424

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1422 - Discy Plugin

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

PLUGIN Discy

CVE-2022-1422

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-0779 - Before 2 Plugin

The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads

PLUGIN Before 2

CVE-2022-0779

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1597 - Wpqa Builder Plugin

The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting attacks

PLUGIN Wpqa Builder

CVE-2022-1597

MEDIUM CVSS 6.1 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1241 - Ask Me Plugin

The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues

PLUGIN Ask Me

CVE-2022-1241

MEDIUM CVSS 6.1 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1005 - Wp Statistics Plugin

The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

PLUGIN Wp Statistics

CVE-2022-1005

MEDIUM CVSS 6.1 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1577 - Database Backup For Plugin

The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which contain more details. Or disable the automatic backup schedule

PLUGIN Database Backup For

CVE-2022-1577

MEDIUM CVSS 5.4 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1506 - Wp Born Babies Plugin

The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Wp Born Babies

CVE-2022-1506

MEDIUM CVSS 5.4 2022-06-08
Scroll to top