Search Results (20883 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-1560 1 Amministrazione Aperta Project 1 Amministrazione Aperta 2024-11-21 6.5 Medium
The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link
CVE-2022-1559 1 Clipr 1 Clipr 2024-11-21 4.8 Medium
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed
CVE-2022-1558 1 Curtain Project 1 Curtain 2024-11-21 4.8 Medium
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
CVE-2022-1557 1 Uleak-security-dashboard Project 1 Uleak-security-dashboard 2024-11-21 5.4 Medium
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks against admins viewing the settings
CVE-2022-1556 1 Era404 1 Stafflist 2024-11-21 9.8 Critical
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection
CVE-2022-1551 1 Smartypantsplugins 1 Sp Project \& Document Manager 2024-11-21 6.5 Medium
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
CVE-2022-1549 1 Wp Athletics Project 1 Wp Athletics 2024-11-21 5.4 Medium
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.
CVE-2022-1547 1 Wpchill 1 Check \& Log Email 2024-11-21 6.1 Medium
The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-1546 1 Visser 1 Woocommerce - Product Importer 2024-11-21 6.1 Medium
The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-1542 1 Justsystems 1 Hpb Dashboard 2024-11-21 4.8 Medium
The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2022-1541 1 Richweb 1 Video Slider 2024-11-21 4.8 Medium
The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1539 1 Exports And Reports Project 1 Exports And Reports 2024-11-21 8.8 High
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.
CVE-2022-1532 1 Themify 1 Woocommerce Product Filter 2024-11-21 6.1 Medium
Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-1528 1 Vikwp 1 Vik Booking 2024-11-21 6.1 Medium
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting
CVE-2022-1527 1 Wpwhitesecurity 1 Wp 2fa 2024-11-21 6.1 Medium
The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-1512 1 Scrollrevealjs-effects Project 1 Scrollrevealjs-effects 2024-11-21 4.8 Medium
The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1506 1 Wp Born Babies Project 1 Wp Born Babies 2024-11-21 5.4 Medium
The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks
CVE-2022-1474 1 Wp-eventmanager 1 Wp Event Manager 2024-11-21 6.1 Medium
The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting
CVE-2022-1472 1 Codesolz 1 Better Find And Replace 2024-11-21 7.2 High
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
CVE-2022-1470 1 Ultimate Woocommerce Csv Importer Project 1 Ultimate Woocommerce Csv Importer 2024-11-21 6.1 Medium
The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting