Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15001-15020 of 16358 records
Threat Entry Updated 2025-05-05

CVE-2022-1187 - Wp Youtube Live Plugin

The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/admin.php file which allows unauthenticated attackers to inject arbitrary web scripts in versions up to, and including, 1.7.21.

PLUGIN Wp Youtube Live

CVE-2022-1187

MEDIUM CVSS 6.1 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2022-1186 - Be Popia Compliant Plugin

The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5.

PLUGIN Be Popia Compliant

CVE-2022-1186

MEDIUM CVSS 5.3 2022-04-19
Threat Entry Updated 2024-11-21

CVE-2022-1091 - Sanitisation Step Of The Safe Svg Plugin

The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).

PLUGIN Sanitisation Step Of The Safe Svg

CVE-2022-1091

MEDIUM CVSS 6.1 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1112 - Autolinks Plugin

The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack

PLUGIN Autolinks

CVE-2022-1112

MEDIUM CVSS 5.4 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1090 - Good Bad Comments Plugin

The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Good Bad Comments

CVE-2022-1090

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1020 - Before 3 Plugin

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

PLUGIN Before 3

CVE-2022-1020

CRITICAL CVSS 9.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0785 - Daily Prayer Time Plugin

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

PLUGIN Daily Prayer Time

CVE-2022-0785

CRITICAL CVSS 9.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1037 - Before 1 Plugin

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

PLUGIN Before 1

CVE-2022-1037

HIGH CVSS 7.2 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0661 - Ad Injection Plugin

The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.

PLUGIN Ad Injection

CVE-2022-0661

HIGH CVSS 7.2 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0879 - Caldera Forms Plugin

The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Caldera Forms

CVE-2022-0879

MEDIUM CVSS 6.1 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0780 - Before 3 Plugin

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

PLUGIN Before 3

CVE-2022-0780

MEDIUM CVSS 6.1 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2021-25120 - Easy Social Feed Plugin

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

PLUGIN Easy Social Feed

CVE-2021-25120

MEDIUM CVSS 6.1 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0765 - Loco Translate Plugin

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

PLUGIN Loco Translate

CVE-2022-0765

MEDIUM CVSS 5.4 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1054 - Rsvp And Event Management Plugin

The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events

PLUGIN Rsvp And Event Management

CVE-2022-1054

MEDIUM CVSS 5.3 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1088 - Page Security Membership Plugin

The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Page Security Membership

CVE-2022-1088

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1063 - Thank Me Later Plugin

The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputting it in the Messages list, which could allow high privileges users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Thank Me Later

CVE-2022-1063

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-1001 - Before 1 Plugin

The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" settings, but does not sanitise and escape it server side, allowing high privilege users such as admin to perform Cross-Site attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2022-1001

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0994 - Before 3 Plugin

The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 3

CVE-2022-0994

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2022-0737 - Before 4 Plugin

The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 4

CVE-2022-0737

MEDIUM CVSS 4.8 2022-04-18
Threat Entry Updated 2025-02-07

CVE-2022-0706 - Before 2 Plugin

The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2022-0706

MEDIUM CVSS 4.8 2022-04-18
Scroll to top