Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15081-15100 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-0641 - Popup Like Box Plugin

The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Popup Like Box

CVE-2022-0641

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0621 - Dtabs Plugin

The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Dtabs

CVE-2022-0621

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0620 - Delete Old Orders Plugin

The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Delete Old Orders

CVE-2022-0620

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0619 - Database Peek Plugin

The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Database Peek

CVE-2022-0619

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0600 - Conference Scheduler Plugin

The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Conference Scheduler

CVE-2022-0600

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0720 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

PLUGIN Before 1

CVE-2022-0720

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0595 - Before 1 Plugin

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2022-0595

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0833 - Church Admin Plugin

The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data

PLUGIN Church Admin

CVE-2022-0833

MEDIUM CVSS 4.3 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0479 - Before 4 Plugin

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

PLUGIN Before 4

CVE-2022-0479

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-25070 - Block Bad Bots Plugin

The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

PLUGIN Block Bad Bots

CVE-2021-25070

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-24962 - Wordpress File Upload Plugin

The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.

PLUGIN Wordpress File Upload

CVE-2021-24962

HIGH CVSS 8.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-25064 - Wow Countdowns Plugin

The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.

PLUGIN Wow Countdowns

CVE-2021-25064

HIGH CVSS 7.2 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-25012 - Pz Linkcard Plugin

The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues

PLUGIN Pz Linkcard

CVE-2021-25012

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-24746 - Social Sharing Plugin

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.

PLUGIN Social Sharing

CVE-2021-24746

MEDIUM CVSS 6.1 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0450 - Icons Made Easy Plugin

The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend

PLUGIN Icons Made Easy

CVE-2022-0450

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0397 - Wpc Smart Wishlist For Woocommerce Plugin

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting

PLUGIN Wpc Smart Wishlist For Woocommerce

CVE-2022-0397

MEDIUM CVSS 5.4 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2021-24978 - Osmapper Plugin

The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a result, unauthenticated user can delete arbitrary posts from the blog

PLUGIN Osmapper

CVE-2021-24978

MEDIUM CVSS 5.3 2022-03-28
Scroll to top