CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-40895

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.

    Published: 27 Jun 2022
    5.4
    Medium

    CVE-2022-2041

    Last Modified: 16 Jan 2025

    The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

    Published: 27 Jun 2022
    5.4
    Medium

    CVE-2022-2040

    Last Modified: 16 Jan 2025

    The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1995

    Last Modified: 21 Nov 2024

    The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1994

    Last Modified: 21 Nov 2024

    The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1990

    Last Modified: 21 Nov 2024

    The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

    Published: 27 Jun 2022
    7.2
    High

    CVE-2022-1977

    Last Modified: 21 Nov 2024

    The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1971

    Last Modified: 21 Nov 2024

    The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 27 Jun 2022
    5.4
    Medium

    CVE-2022-1964

    Last Modified: 21 Nov 2024

    The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1960

    Last Modified: 21 Nov 2024

    The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 27 Jun 2022
    9.1
    Critical

    CVE-2022-1953

    Last Modified: 21 Nov 2024

    The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first

    Published: 27 Jun 2022
    6.1
    Medium

    CVE-2022-1916

    Last Modified: 21 Nov 2024

    The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1914

    Last Modified: 21 Nov 2024

    The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1913

    Last Modified: 21 Nov 2024

    The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

    Published: 27 Jun 2022
    6.1
    Medium

    CVE-2022-1904

    Last Modified: 21 Nov 2024

    The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting

    Published: 27 Jun 2022
    8.1
    High

    CVE-2022-1903

    Last Modified: 21 Nov 2024

    The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1885

    Last Modified: 21 Nov 2024

    The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1847

    Last Modified: 21 Nov 2024

    The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1846

    Last Modified: 21 Nov 2024

    The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1845

    Last Modified: 21 Nov 2024

    The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attackers to make a logged in admin delete plugin's data, update the settings, add new entries and more via CSRF attacks

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1844

    Last Modified: 21 Nov 2024

    The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

    Published: 27 Jun 2022
    6.5
    Medium

    CVE-2022-1843

    Last Modified: 21 Nov 2024

    The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1842

    Last Modified: 21 Nov 2024

    The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

    Published: 27 Jun 2022
    5.4
    Medium

    CVE-2022-1776

    Last Modified: 21 Nov 2024

    The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1653

    Last Modified: 21 Nov 2024

    The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1627

    Last Modified: 21 Nov 2024

    The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1625

    Last Modified: 21 Nov 2024

    The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.

    Published: 27 Jun 2022
    6.1
    Medium

    CVE-2022-1593

    Last Modified: 21 Nov 2024

    The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF attack

    Published: 27 Jun 2022
    9.8
    Critical

    CVE-2022-1574

    Last Modified: 21 Nov 2024

    The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-1573

    Last Modified: 21 Nov 2024

    The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them

    Published: 27 Jun 2022
    8.1
    High

    CVE-2022-1572

    Last Modified: 21 Nov 2024

    The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

    Published: 27 Jun 2022
    6.1
    Medium

    CVE-2022-1470

    Last Modified: 21 Nov 2024

    The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1327

    Last Modified: 21 Nov 2024

    The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1326

    Last Modified: 21 Nov 2024

    The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1321

    Last Modified: 21 Nov 2024

    The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1113

    Last Modified: 21 Nov 2024

    The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups)

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1095

    Last Modified: 21 Nov 2024

    The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1029

    Last Modified: 21 Nov 2024

    The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1028

    Last Modified: 21 Nov 2024

    The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

    Published: 27 Jun 2022
    4.8
    Medium

    CVE-2022-1010

    Last Modified: 21 Nov 2024

    The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-0875

    Last Modified: 21 Nov 2024

    The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-0444

    Last Modified: 21 Nov 2024

    The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

    Published: 27 Jun 2022
    6.3
    Medium

    CVE-2022-2214

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Library Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /librarian/bookdetails.php. The manipulation of the argument id with the input ' AND (SELECT 9198 FROM (SELECT(SLEEP(5)))iqZA)-- PbtB leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Jun 2022
    3.5
    Low

    CVE-2022-2213

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_admin_details.php?id=admin. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Jun 2022
    6.3
    Medium

    CVE-2022-2212

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the component /card/index.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Jun 2022
    5.3
    Medium

    CVE-2020-9754

    Last Modified: 21 Nov 2024

    NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.

    Published: 27 Jun 2022
    8.1
    High

    CVE-2022-33202

    Last Modified: 21 Nov 2024

    Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by using alternative paths or channels for Sensor.

    Published: 27 Jun 2022
    6.1
    Medium

    CVE-2022-33146

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

    Published: 27 Jun 2022
    7.5
    High

    CVE-2022-0722

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.

    Published: 27 Jun 2022
    0
    Low

    CVE-2022-2220

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 27 Jun 2022