Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15041-15060 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-0471 - Before 1 Plugin

The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-0471

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0314 - Nimble Page Builder Plugin

The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Nimble Page Builder

CVE-2022-0314

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0271 - Before 4 Plugin

The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting

PLUGIN Before 4

CVE-2022-0271

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2021-25090 - Product Catalog Plugin

The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed

PLUGIN Product Catalog

CVE-2021-25090

MEDIUM CVSS 5.4 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0919 - Salon Booking System Plugin

The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it.

PLUGIN Salon Booking System

CVE-2022-0919

MEDIUM CVSS 5.3 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0246 - Settings Of The Iq Block Country Plugin

The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the extraction process, existence of a file is checked. If the file exists, it is deleted without any security control by only considering the name of the extracted file. This behavior leads to "Zip Slip" vulnerability.

PLUGIN Settings Of The Iq Block Country

CVE-2022-0246

MEDIUM CVSS 4.9 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0969 - Lazy Load By Optimole Plugin

The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Lazy Load By Optimole

CVE-2022-0969

MEDIUM CVSS 4.8 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0840 - Easy Social Icons Plugin

The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.

PLUGIN Easy Social Icons

CVE-2022-0840

MEDIUM CVSS 4.8 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-0728 - Easy Smooth Scroll Links Plugin

The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Easy Smooth Scroll Links

CVE-2022-0728

MEDIUM CVSS 4.8 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2021-24987 - Social Login And Social Comments Plugin

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

PLUGIN Social Login And Social Comments

CVE-2021-24987

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2021-24986 - Post Grid Plugin

The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form

PLUGIN Post Grid

CVE-2021-24986

MEDIUM CVSS 6.1 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2022-1170 - Jobmonster Plugin

In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

PLUGIN Jobmonster

CVE-2022-1170

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-1165 - Blackhole For Bad Bots Plugin

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.

PLUGIN Blackhole For Bad Bots

CVE-2022-1165

CRITICAL CVSS 9.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0887 - Easy Social Icons Plugin

The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

PLUGIN Easy Social Icons

CVE-2022-0887

HIGH CVSS 7.2 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-1167 - Careerup Plugin

There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters.

PLUGIN Careerup

CVE-2022-1167

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0901 - Ad Inserter Plugin

The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

PLUGIN Ad Inserter

CVE-2022-0901

MEDIUM CVSS 6.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0958 - Before 2 Plugin

The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2022-0958

MEDIUM CVSS 4.8 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0403 - Library File Manager Plugin

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

PLUGIN Library File Manager

CVE-2022-0403

HIGH CVSS 8.1 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0709 - Booking Package Plugin

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

PLUGIN Booking Package

CVE-2022-0709

HIGH CVSS 7.5 2022-04-04
Scroll to top