Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14921-14940 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-1281 - Photo Gallery Plugin

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

PLUGIN Photo Gallery

CVE-2022-1281

CRITICAL CVSS 9.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1273 - Import Wp Plugin

The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE

PLUGIN Import Wp

CVE-2022-1273

HIGH CVSS 7.2 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1282 - Photo Gallery By 10web Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.

PLUGIN Photo Gallery By 10web

CVE-2022-1282

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0783 - Multiple Shipping Address Woocommerce Plugin

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

PLUGIN Multiple Shipping Address Woocommerce

CVE-2022-0783

CRITICAL CVSS 9.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0773 - Documentor Plugin

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

PLUGIN Documentor

CVE-2022-0773

CRITICAL CVSS 9.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0771 - Before 5 Plugin

The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections

PLUGIN Before 5

CVE-2022-0771

CRITICAL CVSS 9.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1239 - Before 8 Plugin

The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks

PLUGIN Before 8

CVE-2022-1239

HIGH CVSS 8.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0952 - Sitemap By Click5 Plugin

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

PLUGIN Sitemap By Click5

CVE-2022-0952

HIGH CVSS 8.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0191 - Before 1 Plugin

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans

PLUGIN Before 1

CVE-2022-0191

MEDIUM CVSS 6.5 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1269 - Before 1 Plugin

The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2022-1269

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1250 - Lifterlms Paypal Plugin

The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Lifterlms Paypal

CVE-2022-1250

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0428 - Before 5 Plugin

The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 5

CVE-2022-0428

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2021-25086 - Advanced Page Visit Counter Plugin

The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it

PLUGIN Advanced Page Visit Counter

CVE-2021-25086

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1255 - Import And Export Users And Customers Plugin

The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

PLUGIN Import And Export Users And Customers

CVE-2022-1255

MEDIUM CVSS 4.8 2022-05-02
Scroll to top