Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2022-1046 - Visual Form Builder Plugin
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-1046
CVE-2022-0662 - Before 5 Plugin
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0662
CVE-2022-0649 - Before 5 Plugin
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0649
CVE-2022-0418 - Event List Plugin
The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed
CVE-2022-0418
CVE-2021-25102 - Before 4 Plugin
The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk
CVE-2021-25102
CVE-2021-25002 - Before 1 Plugin
The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL
CVE-2021-25002
CVE-2022-29451 - Rara One Click Demo Import Plugin
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin
CVE-2022-29451
CVE-2022-29414 - Subscribe To Comments Reloaded Plugin
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin mass update settings, manage subscriptions > add a new subscription, update subscription, delete Subscription.
CVE-2022-29414
CVE-2022-29411 - Hermit Plugin
SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin
CVE-2022-29411
CVE-2022-29412 - Hermit Plugin
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin
CVE-2022-29412
CVE-2022-29413 - Hermit Plugin
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin
CVE-2022-29413
CVE-2022-29410 - Hermit Plugin
Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin
CVE-2022-29410
CVE-2022-29415 - Ravpage Plugin
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin
CVE-2022-29415
CVE-2022-27860 - Footer Text Plugin
Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin
CVE-2022-27860
CVE-2022-27854 - Psychological Tests Quizzes Plugin
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin
CVE-2022-27854
CVE-2021-36867 - Psychological Tests Quizzes Plugin
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin
CVE-2021-36867
CVE-2021-36895 - Tripetto Plugin
Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin
CVE-2021-36895
CVE-2022-29419 - 3xsocializer Plugin
SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin
CVE-2022-29419
CVE-2022-29418 - Night Mode Plugin
Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin
CVE-2022-29418
CVE-2022-29417 - Shortpixel Adaptive Images Plugin
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin
CVE-2022-29417
