Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1101-1120 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2022-2754 - Ketchup Restaurant Reservations Plugin

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

PLUGIN Ketchup Restaurant Reservations

CVE-2022-2754

CRITICAL CVSS 9.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-2180 - Greyd Suite Plugin

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

PLUGIN Greyd Suite

CVE-2022-2180

CRITICAL CVSS 9.8 2022-08-15
Threat Entry Updated 2025-09-03

CVE-2022-2460 - Before 7 Plugin

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

PLUGIN Before 7

CVE-2022-2460

CRITICAL CVSS 9.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2269 - Website File Changes Monitor Plugin

The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection

PLUGIN Website File Changes Monitor

CVE-2022-2269

CRITICAL CVSS 9.8 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-2317 - Simple Membership Plugin

The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.

PLUGIN Simple Membership

CVE-2022-2317

CRITICAL CVSS 9.8 2022-08-01
Threat Entry Updated 2024-11-21

CVE-2022-1950 - Before 1 Plugin

The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

PLUGIN Before 1

CVE-2022-1950

CRITICAL CVSS 9.8 2022-08-01
Threat Entry Updated 2025-05-05

CVE-2022-2437 - Feed Them Social Plugin

The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

PLUGIN Feed Them Social

CVE-2022-2437

CRITICAL CVSS 9.8 2022-07-18
Threat Entry Updated 2026-01-23

CVE-2022-1952 - Restaurant And Car Rental Plugin

The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.

PLUGIN Restaurant And Car Rental

CVE-2022-1952

CRITICAL CVSS 9.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1057 - Pricing Deals For Woocommerce Plugin

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

PLUGIN Pricing Deals For Woocommerce

CVE-2022-1057

CRITICAL CVSS 9.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2022-1953 - Product Configurator For Woocommerce Plugin

The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first

PLUGIN Product Configurator For Woocommerce

CVE-2022-1953

CRITICAL CVSS 9.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1574 - Html2wp Plugin

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

PLUGIN Html2wp

CVE-2022-1574

CRITICAL CVSS 9.8 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2022-1905 - Events Made Easy Plugin

The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PLUGIN Events Made Easy

CVE-2022-1905

CRITICAL CVSS 9.8 2022-06-20
Scroll to top