Search Results (327847 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-2386 1 Automattic 1 Crowdsignal Dashboard 2024-11-21 6.1 Medium
The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2385 1 Kubernetes 1 Aws-iam-authenticator 2024-11-21 8.1 High
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
CVE-2022-2384 1 Supsystic 1 Digital Publications By Supsystic 2024-11-21 4.8 Medium
The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2383 1 Slickremix 1 Feed Them Social 2024-11-21 6.1 Medium
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2382 1 Shapedplugin 1 Product Slider For Woocommerce 2024-11-21 4.3 Medium
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.
CVE-2022-2381 1 E Unlocked - Student Result Project 1 E Unlocked - Student Result 2024-11-21 8.8 High
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack
CVE-2022-2379 1 Easy Student Results Project 1 Easy Student Results 2024-11-21 7.5 High
The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc
CVE-2022-2378 1 Easy Student Results Project 1 Easy Student Results 2024-11-21 6.1 Medium
The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2377 1 Wpwax 1 Directorist 2024-11-21 4.3 Medium
The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog
CVE-2022-2376 1 Wpwax 1 Directorist 2024-11-21 5.3 Medium
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
CVE-2022-2375 1 Okapitech 1 Wp Sticky Button 2024-11-21 5.4 Medium
The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues
CVE-2022-2374 1 Nsqua 1 Simply Schedule Appointments 2024-11-21 4.8 Medium
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2373 1 Nsqua 1 Simply Schedule Appointments 2024-11-21 5.3 Medium
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
CVE-2022-2372 1 Yaycommerce 1 Yaysmtp 2024-11-21 4.8 Medium
The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2371 1 Yaycommerce 1 Yaysmtp 2024-11-21 5.4 Medium
The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.
CVE-2022-2370 1 Yaycommerce 1 Yaysmtp 2024-11-21 6.5 Medium
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
CVE-2022-2369 1 Yaycommerce 1 Yaysmtp 2024-11-21 4.3 Medium
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
CVE-2022-2368 1 Microweber 1 Microweber 2024-11-21 6.5 Medium
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
CVE-2022-2367 1 Wsm Downloader Project 1 Wsm Downloader 2024-11-21 7.5 High
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation
CVE-2022-2365 1 Trilium Project 1 Trilium 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.