CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-0385

    Last Modified: 21 Nov 2024

    The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

    Published: 28 Feb 2022
    7.2
    High

    CVE-2022-0383

    Last Modified: 21 Nov 2024

    The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks

    Published: 28 Feb 2022
    4.3
    Medium

    CVE-2022-0377

    Last Modified: 21 Nov 2024

    Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of this request, the name of the user-supplied image is changed with a MD5 value. This process can be conducted only when type of the image is JPG or PNG. An attacker can use this vulnerability in order to rename an arbitrary image file. By doing this, they could destroy the design of the web site.

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2022-0360

    Last Modified: 21 Nov 2024

    The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

    Published: 28 Feb 2022
    4.3
    Medium

    CVE-2022-0345

    Last Modified: 21 Nov 2024

    The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).

    Published: 28 Feb 2022
    4.7
    Medium

    CVE-2022-0328

    Last Modified: 21 Nov 2024

    The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-0189

    Last Modified: 21 Nov 2024

    The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-0150

    Last Modified: 21 Nov 2024

    The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2021-4222

    Last Modified: 21 Nov 2024

    The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 28 Feb 2022
    5.3
    Medium

    CVE-2021-25118

    Last Modified: 21 Nov 2024

    The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2021-25112

    Last Modified: 21 Nov 2024

    The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

    Published: 28 Feb 2022
    6.5
    Medium

    CVE-2021-25081

    Last Modified: 21 Nov 2024

    The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2021-25042

    Last Modified: 6 Mar 2026

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in admin

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2021-25034

    Last Modified: 21 Nov 2024

    The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues

    Published: 28 Feb 2022
    5.7
    Medium

    CVE-2021-25011

    Last Modified: 21 Nov 2024

    The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

    Published: 28 Feb 2022
    9.6
    Critical

    CVE-2021-25010

    Last Modified: 21 Nov 2024

    The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2021-24994

    Last Modified: 21 Nov 2024

    The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2021-24977

    Last Modified: 13 Jan 2026

    The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the frontend for all users. Due to the lack of sanitisation and escaping in the backend, it could also lead to Stored XSS issues

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2021-24971

    Last Modified: 21 Nov 2024

    The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting attacks against all visitor and users on the frontend

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2021-24933

    Last Modified: 21 Nov 2024

    The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2021-24920

    Last Modified: 21 Nov 2024

    The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 28 Feb 2022
    4.3
    Medium

    CVE-2021-24913

    Last Modified: 21 Nov 2024

    The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in high privilege user, change title, description, alt text, and URL of arbitrary uploaded media.

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2021-24903

    Last Modified: 21 Nov 2024

    The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2021-24901

    Last Modified: 21 Nov 2024

    The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2021-24898

    Last Modified: 21 Nov 2024

    The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 28 Feb 2022
    8.8
    High

    CVE-2021-24864

    Last Modified: 21 Nov 2024

    The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue

    Published: 28 Feb 2022
    8.1
    High

    CVE-2021-24823

    Last Modified: 21 Nov 2024

    The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

    Published: 28 Feb 2022
    6.5
    Medium

    CVE-2021-24820

    Last Modified: 21 Nov 2024

    The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout

    Published: 28 Feb 2022
    8.8
    High

    CVE-2021-24803

    Last Modified: 21 Nov 2024

    The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create another admin account and takeover the website via CSRF attacks

    Published: 28 Feb 2022
    4.3
    Medium

    CVE-2021-24730

    Last Modified: 21 Nov 2024

    The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of arbitrary uploaded media.

    Published: 28 Feb 2022
    8.8
    High

    CVE-2021-24704

    Last Modified: 21 Nov 2024

    In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF protection, it is actually exploitable and could allow attackers to make a logged in admin delete arbitrary posts for example

    Published: 28 Feb 2022
    4.9
    Medium

    CVE-2021-24689

    Last Modified: 21 Nov 2024

    The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack

    Published: 28 Feb 2022
    4.3
    Medium

    CVE-2021-24688

    Last Modified: 21 Nov 2024

    The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers to delete arbitrary posts.The AJAX calls performing actions on posts also do not ensure that the post belong to them (or that they are allowed to perform such action on it)

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2020-36510

    Last Modified: 21 Nov 2024

    The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the response via the cb_s_a AJAX action, leading to a Reflected Cross-Site Scripting

    Published: 28 Feb 2022
    5.3
    Medium

    CVE-2022-26159

    Last Modified: 21 Nov 2024

    The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2021-43945

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.

    Published: 28 Feb 2022
    5.6
    Medium

    CVE-2022-0675

    Last Modified: 21 Nov 2024

    In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

    Published: 28 Feb 2022
    4.3
    Medium

    CVE-2022-23708

    Last Modified: 21 Nov 2024

    A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

    Published: 28 Feb 2022
    4.3
    Medium

    CVE-2022-23709

    Last Modified: 21 Nov 2024

    A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-23710

    Last Modified: 21 Nov 2024

    A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

    Published: 28 Feb 2022
    3.2
    Low

    CVE-2022-26354

    Last Modified: 21 Nov 2024

    A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2022-0772

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2.

    Published: 27 Feb 2022
    5.5
    Medium

    CVE-2022-2380

    Last Modified: 23 Apr 2025

    The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.

    Published: 27 Feb 2022
    8.8
    High

    CVE-2021-3967

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

    Published: 26 Feb 2022
    5.5
    Medium

    CVE-2022-22908

    Last Modified: 21 Nov 2024

    SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.

    Published: 26 Feb 2022
    5.4
    Medium

    CVE-2022-26146

    Last Modified: 21 Nov 2024

    Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker.

    Published: 26 Feb 2022
    4.3
    Medium

    CVE-2020-27958

    Last Modified: 21 Nov 2024

    The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.

    Published: 26 Feb 2022
    6.7
    Medium

    CVE-2022-0764

    Last Modified: 21 Nov 2024

    Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

    Published: 26 Feb 2022
    5.4
    Medium

    CVE-2022-0723

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.

    Published: 26 Feb 2022
    4.8
    Medium

    CVE-2022-0763

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.

    Published: 26 Feb 2022