Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1121-1140 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2022-1768 - Rsvpmaker Plugin

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

PLUGIN Rsvpmaker

CVE-2022-1768

CRITICAL CVSS 9.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-0885 - Member Hero Plugin

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

PLUGIN Member Hero

CVE-2022-0885

CRITICAL CVSS 9.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-0827 - Bestbooks Plugin

The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

PLUGIN Bestbooks

CVE-2022-0827

CRITICAL CVSS 9.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-0786 - Before 2 Plugin

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

PLUGIN Before 2

CVE-2022-0786

CRITICAL CVSS 9.8 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1692 - Cp Image Store With Slideshow Plugin

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

PLUGIN Cp Image Store With Slideshow

CVE-2022-1692

CRITICAL CVSS 9.8 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1556 - Before 3 Plugin

The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

PLUGIN Before 3

CVE-2022-1556

CRITICAL CVSS 9.8 2022-05-30
Threat Entry Updated 2024-11-21

CVE-2022-1014 - Wp Contacts Manager Plugin

The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.

PLUGIN Wp Contacts Manager

CVE-2022-1014

CRITICAL CVSS 9.8 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-0781 - Nirweb Support Plugin

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

PLUGIN Nirweb Support

CVE-2022-0781

CRITICAL CVSS 9.8 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2022-1386 - Fusion Builder Plugin

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

PLUGIN Fusion Builder

CVE-2022-1386

CRITICAL CVSS 9.8 2022-05-16
Threat Entry Updated 2024-11-21

CVE-2022-0867 - Pricing Table Plugin

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

PLUGIN Pricing Table

CVE-2022-0867

CRITICAL CVSS 9.8 2022-05-16
Threat Entry Updated 2025-05-05

CVE-2022-1505 - Rsvpmaker Plugin

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6.

PLUGIN Rsvpmaker

CVE-2022-1505

CRITICAL CVSS 9.8 2022-05-10
Threat Entry Updated 2025-05-05

CVE-2022-1453 - Rsvpmaker Plugin

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

PLUGIN Rsvpmaker

CVE-2022-1453

CRITICAL CVSS 9.8 2022-05-10
Threat Entry Updated 2024-11-21

CVE-2022-1013 - Personal Dictionary Plugin

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

PLUGIN Personal Dictionary

CVE-2022-1013

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0948 - Order Listener For Woocommerce Plugin

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

PLUGIN Order Listener For Woocommerce

CVE-2022-0948

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0836 - Sema Api Plugin

The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users

PLUGIN Sema Api

CVE-2022-0836

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0826 - Wp Video Gallery Free Plugin

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

PLUGIN Wp Video Gallery Free

CVE-2022-0826

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0817 - Badgeos Plugin

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

PLUGIN Badgeos

CVE-2022-0817

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0814 - Para Woocommerce Plugin

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

PLUGIN Para Woocommerce

CVE-2022-0814

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2022-0592 - Before 6 Plugin

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

PLUGIN Before 6

CVE-2022-0592

CRITICAL CVSS 9.8 2022-05-09
Scroll to top