Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15121-15140 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-0364 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Modern Events Calendar Lite

CVE-2022-0364

MEDIUM CVSS 5.4 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0590 - Bulletproof Security Plugin

The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Bulletproof Security

CVE-2022-0590

MEDIUM CVSS 4.8 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-0616 - Before 1 Plugin

The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack

PLUGIN Before 1

CVE-2022-0616

MEDIUM CVSS 4.3 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2021-25019 - Seo Plugin By Squirrly Seo

The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Seo Plugin By Squirrly Seo

CVE-2021-25019

MEDIUM CVSS 6.1 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2021-24905 - Advanced Contact Form 7 Db Plugin

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.

PLUGIN Advanced Contact Form 7 Db

CVE-2021-24905

HIGH CVSS 8.0 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2022-25603 - Maxgalleria Plugin

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5).

PLUGIN Maxgalleria

CVE-2022-25603

MEDIUM CVSS 4.8 2022-03-18
Threat Entry Updated 2024-11-21

CVE-2022-25604 - Price Table Plugin

Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Price Table plugin (versions

PLUGIN Price Table

CVE-2022-25604

MEDIUM CVSS 4.1 2022-03-18
Threat Entry Updated 2024-11-21

CVE-2022-22735 - Simple Quotation Plugin

The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenticated users, such as subscriber to perform SQL injection attacks

PLUGIN Simple Quotation

CVE-2022-22735

HIGH CVSS 8.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0658 - Before 2 Plugin

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

PLUGIN Before 2

CVE-2022-0658

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0593 - Login With Phone Number Plugin

The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.

PLUGIN Login With Phone Number

CVE-2022-0593

MEDIUM CVSS 6.5 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-22734 - Simple Quotation Plugin

The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does not sanitise and escape Quotes. As a result, attacker could make a logged in admin create or edit arbitrary quote, and put Cross-Site Scripting payloads in them

PLUGIN Simple Quotation

CVE-2022-22734

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0601 - Maintenance Plugin

The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PLUGIN Maintenance

CVE-2022-0601

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0503 - Before 2 Plugin

The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in the network dashboard

PLUGIN Before 2

CVE-2022-0503

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0703 - Gd Mylist Plugin

The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Gd Mylist

CVE-2022-0703

MEDIUM CVSS 4.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0702 - Petfinder Listings Plugin

The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Petfinder Listings

CVE-2022-0702

MEDIUM CVSS 4.8 2022-03-14
Scroll to top