Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14821-14840 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1562 - Enable Svg Plugin

The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

PLUGIN Enable Svg

CVE-2022-1562

MEDIUM CVSS 5.4 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1566 - Quotes Llama Plugin

The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by tricking an admin to import a malicious CSV file

PLUGIN Quotes Llama

CVE-2022-1566

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1564 - Form Maker By 10web Plugin

The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Form Maker By 10web

CVE-2022-1564

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1542 - Hpb Dashboard Plugin

The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Hpb Dashboard

CVE-2022-1542

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1456 - Before 4 Plugin

The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed

PLUGIN Before 4

CVE-2022-1456

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1395 - Easy Faq With Expanding Text Plugin

The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

PLUGIN Easy Faq With Expanding Text

CVE-2022-1395

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1387 - No Future Posts Plugin

The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

PLUGIN No Future Posts

CVE-2022-1387

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1299 - Slideshow Plugin

The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Slideshow

CVE-2022-1299

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1294 - Imdb Info Box Plugin

The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Imdb Info Box

CVE-2022-1294

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1275 - Bannerman Plugin

The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in multisite)

PLUGIN Bannerman

CVE-2022-1275

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1203 - Content Mask Plugin

The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog options

PLUGIN Content Mask

CVE-2022-1203

MEDIUM CVSS 4.3 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1009 - Before 3 Plugin

The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker would need an admin to upload a malicious configuration file

PLUGIN Before 3

CVE-2022-1009

MEDIUM CVSS 6.1 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-0642 - Jivochat Live Chat Plugin

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

PLUGIN Jivochat Live Chat

CVE-2022-0642

MEDIUM CVSS 5.4 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-0376 - Before 2 Plugin

The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 2

CVE-2022-0376

MEDIUM CVSS 4.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1547 - Before 1 Plugin

The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-1547

MEDIUM CVSS 6.1 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1268 - Donate Extra Plugin

The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting

PLUGIN Donate Extra

CVE-2022-1268

MEDIUM CVSS 6.1 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1558 - Curtain Plugin

The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Curtain

CVE-2022-1558

MEDIUM CVSS 4.8 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1320 - Before 1 Plugin

The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 1

CVE-2022-1320

MEDIUM CVSS 4.8 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1298 - Before 2 Plugin

The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2022-1298

MEDIUM CVSS 4.8 2022-05-23
Scroll to top