Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14881-14900 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1393 - Before 3 Plugin

The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subtitle]. The subtitle is stored as a custom post meta with the key: "wps_subtitle", which is sanitized upon post save/update, however is not sanitized when updating it directly from the post meta update button (via AJAX) - and this makes the XSS exploitable by authenticated users with a role as low as contributor.

PLUGIN Before 3

CVE-2022-1393

MEDIUM CVSS 5.4 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1512 - Scrollrevealjs Effects Plugin

The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Scrollrevealjs Effects

CVE-2022-1512

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1435 - Before 6 Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Before 6

CVE-2022-1435

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1408 - Before 1 Plugin

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Before 1

CVE-2022-1408

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1334 - Wp Youtube Live Plugin

The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Wp Youtube Live

CVE-2022-1334

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1265 - Bulletproof Security Plugin

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PLUGIN Bulletproof Security

CVE-2022-1265

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1425 - Wpqa Builder Plugin

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being able to read messages for any other users via a Insecure Direct Object Reference (IDOR) vulnerability.

PLUGIN Wpqa Builder

CVE-2022-1425

MEDIUM CVSS 4.3 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1349 - Wpqa Builder Plugin

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as low as Subscriber) to delete the profile pictures of any other user.

PLUGIN Wpqa Builder

CVE-2022-1349

MEDIUM CVSS 4.3 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-0867 - Pricing Table Plugin

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

PLUGIN Pricing Table

CVE-2022-0867

CRITICAL CVSS 9.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1182 - Visual Slide Box Builder Plugin

The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL Injections

PLUGIN Visual Slide Box Builder

CVE-2022-1182

HIGH CVSS 8.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2021-25119 - Automatic Grid Image Listing Plugin

The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

PLUGIN Automatic Grid Image Listing

CVE-2021-25119

HIGH CVSS 7.2 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1051 - Wpqa Builder Plugin

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.

PLUGIN Wpqa Builder

CVE-2022-1051

MEDIUM CVSS 5.4 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1089 - Bulk Edit And Create User Profiles Plugin

The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Bulk Edit And Create User Profiles

CVE-2022-1089

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-1062 - Th23 Social Plugin

The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Th23 Social

CVE-2022-1062

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-0873 - Gmedia Photo Gallery Plugin

The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

PLUGIN Gmedia Photo Gallery

CVE-2022-0873

MEDIUM CVSS 4.8 2022-05-16
Threat Entry Updated 2025-05-05

CVE-2022-1505 - Rsvpmaker Plugin

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6.

PLUGIN Rsvpmaker

CVE-2022-1505

CRITICAL CVSS 9.8 2022-05-10
Threat Entry Updated 2025-05-05

CVE-2022-1453 - Rsvpmaker Plugin

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

PLUGIN Rsvpmaker

CVE-2022-1453

CRITICAL CVSS 9.8 2022-05-10
Threat Entry Updated 2024-11-21

CVE-2022-1463 - Booking Calendar Plugin

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.

PLUGIN Booking Calendar

CVE-2022-1463

HIGH CVSS 8.8 2022-05-10
Scroll to top