Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14801-14820 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1598 - Wpqa Builder Plugin

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

PLUGIN Wpqa Builder

CVE-2022-1598

MEDIUM CVSS 5.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1569 - Before 1 Plugin

The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

PLUGIN Before 1

CVE-2022-1569

MEDIUM CVSS 4.8 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1541 - Video Slider Plugin

The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Video Slider

CVE-2022-1541

MEDIUM CVSS 4.8 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1469 - Before 1 Plugin

The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2022-1469

MEDIUM CVSS 4.8 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1394 - Photo Gallery By 10web Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

PLUGIN Photo Gallery By 10web

CVE-2022-1394

MEDIUM CVSS 4.8 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1421 - Discy Plugin

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

PLUGIN Discy

CVE-2022-1421

MEDIUM CVSS 4.3 2022-06-08
Threat Entry Updated 2026-01-14

CVE-2022-1589 - Change Wp Admin Login Plugin

The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector

PLUGIN Change Wp Admin Login

CVE-2022-1589

HIGH CVSS 7.5 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1583 - Before 1 Plugin

The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.

PLUGIN Before 1

CVE-2022-1583

MEDIUM CVSS 6.5 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1582 - Before 1 Plugin

The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.

PLUGIN Before 1

CVE-2022-1582

MEDIUM CVSS 6.1 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1646 - Simple Real Estate Pack Plugin

The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Simple Real Estate Pack

CVE-2022-1646

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1645 - Amazon Link Plugin

The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Amazon Link

CVE-2022-1645

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1644 - Call Book Mobile Bar Plugin

The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Call Book Mobile Bar

CVE-2022-1644

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1643 - Birthdays Widget Plugin

The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Birthdays Widget

CVE-2022-1643

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1568 - Team Members Plugin

The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Team Members

CVE-2022-1568

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1556 - Before 3 Plugin

The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

PLUGIN Before 3

CVE-2022-1556

CRITICAL CVSS 9.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1528 - Before 1 Plugin

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-1528

MEDIUM CVSS 6.1 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1527 - Before 2 Plugin

The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-1527

MEDIUM CVSS 6.1 2022-05-30
Scroll to top