Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14861-14880 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1560 - Amministrazione Aperta Plugin

The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link

PLUGIN Amministrazione Aperta

CVE-2022-1560

MEDIUM CVSS 6.5 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1557 - Uleak Security Dashboard Plugin

The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks against admins viewing the settings

PLUGIN Uleak Security Dashboard

CVE-2022-1557

MEDIUM CVSS 5.4 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1559 - Clipr Plugin

The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed

PLUGIN Clipr

CVE-2022-1559

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1386 - Fusion Builder Plugin

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

PLUGIN Fusion Builder

CVE-2022-1386

CRITICAL CVSS 9.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1409 - Before 1 Plugin

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code

PLUGIN Before 1

CVE-2022-1409

HIGH CVSS 7.2 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1407 - Before 1 Plugin

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via a CSRF attack

PLUGIN Before 1

CVE-2022-1407

MEDIUM CVSS 6.5 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1398 - External Media Without Import Plugin

The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks

PLUGIN External Media Without Import

CVE-2022-1398

MEDIUM CVSS 6.5 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1465 - Wpc Smart Wishlist For Woocommerce Plugin

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.

PLUGIN Wpc Smart Wishlist For Woocommerce

CVE-2022-1465

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1455 - Call Now Button Plugin

The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled

PLUGIN Call Now Button

CVE-2022-1455

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1436 - Before 6 Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.

PLUGIN Before 6

CVE-2022-1436

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1418 - Social Stickers Plugin

The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.

PLUGIN Social Stickers

CVE-2022-1418

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1267 - Bmi Bmr Calculator Plugin

The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Bmi Bmr Calculator

CVE-2022-1267

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1217 - Custom Tinymce Shortcode Button Plugin

The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.

PLUGIN Custom Tinymce Shortcode Button

CVE-2022-1217

MEDIUM CVSS 6.1 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1216 - Advanced Image Sitemap Plugin

The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.

PLUGIN Advanced Image Sitemap

CVE-2022-1216

MEDIUM CVSS 6.1 2022-05-16
Scroll to top