Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14841-14860 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1014 - Wp Contacts Manager Plugin

The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.

PLUGIN Wp Contacts Manager

CVE-2022-1014

CRITICAL CVSS 9.8 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-0781 - Nirweb Support Plugin

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

PLUGIN Nirweb Support

CVE-2022-0781

CRITICAL CVSS 9.8 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1221 - Gwyn S Imagemap Selector Plugin

The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

PLUGIN Gwyn S Imagemap Selector

CVE-2022-1221

MEDIUM CVSS 6.1 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1218 - Domain Replace Plugin

The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Domain Replace

CVE-2022-1218

MEDIUM CVSS 6.1 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1192 - Turn Off All Comments Plugin

The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Turn Off All Comments

CVE-2022-1192

MEDIUM CVSS 6.1 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-0346 - Xml Sitemap Generator For Google Plugin

The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.

PLUGIN Xml Sitemap Generator For Google

CVE-2022-0346

MEDIUM CVSS 6.1 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1093 - Before 4 Plugin

The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed.

PLUGIN Before 4

CVE-2022-1093

MEDIUM CVSS 4.8 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-29426 - 2j Slideshow Plugin

Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin

PLUGIN 2j Slideshow

CVE-2022-29426

MEDIUM CVSS 5.4 2022-05-20
Scroll to top