Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15101-15120 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-0493 - String Locator Plugin

The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.

PLUGIN String Locator

CVE-2022-0493

MEDIUM CVSS 4.9 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0388 - Interactive Medical Drawing Of Human Body Plugin

The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Interactive Medical Drawing Of Human Body

CVE-2022-0388

MEDIUM CVSS 4.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0888 - Ninja Forms File Uploads Extension Plugin

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0

PLUGIN Ninja Forms File Uploads Extension

CVE-2022-0888

CRITICAL CVSS 9.8 2022-03-23
Threat Entry Updated 2024-11-21

CVE-2022-0889 - Ninja Forms File Uploads Extension Plugin

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.

PLUGIN Ninja Forms File Uploads Extension

CVE-2022-0889

HIGH CVSS 7.2 2022-03-23
Threat Entry Updated 2024-11-21

CVE-2022-0834 - Amelia Plugin

The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.

PLUGIN Amelia

CVE-2022-0834

HIGH CVSS 7.2 2022-03-23
Threat Entry Updated 2025-05-05

CVE-2022-0750 - Photoswipe Masonry Gallery Plugin

The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height parameters found in the ~/photoswipe-masonry.php file which allows authenticated attackers to inject arbitrary web scripts into galleries created by the plugin and on the PhotoSwipe Options page. This affects versions up to and including 1.2.14.

PLUGIN Photoswipe Masonry Gallery

CVE-2022-0750

MEDIUM CVSS 6.4 2022-03-23
Threat Entry Updated 2024-11-21

CVE-2022-0760 - Simple Link Directory Plugin

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

PLUGIN Simple Link Directory

CVE-2022-0760

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0747 - Before 4 Plugin

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

PLUGIN Before 4

CVE-2022-0747

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0739 - Before 1 Plugin

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

PLUGIN Before 1

CVE-2022-0739

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0694 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Advanced Booking Calendar

CVE-2022-0694

CRITICAL CVSS 9.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0687 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

PLUGIN Before 1

CVE-2022-0687

HIGH CVSS 8.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0681 - Simple Membership Plugin

The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack

PLUGIN Simple Membership

CVE-2022-0681

MEDIUM CVSS 6.5 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0640 - Pricing Table Builder Plugin

The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Pricing Table Builder

CVE-2022-0640

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0628 - Before 3 Plugin

The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 3

CVE-2022-0628

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0627 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Before 1

CVE-2022-0627

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0591 - Before 3 Plugin

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

PLUGIN Before 3

CVE-2022-0591

CRITICAL CVSS 9.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0229 - S Google Authenticator Plugin

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

PLUGIN S Google Authenticator

CVE-2022-0229

HIGH CVSS 8.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0423 - 3d Flipbook Plugin

The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.

PLUGIN 3d Flipbook

CVE-2022-0423

MEDIUM CVSS 5.4 2022-03-21
Scroll to top