1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-2260
GiveWP – Donation Plugin and Fundraising Platform DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU.

CVE-2022-1781
postTabs Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-0781
Nirweb support Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.9%
2022 CWE-89 1 PoC

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

CVE-2022-3209
soledad Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-2567
Form Builder CP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0478
Event Manager and Tickets Selling Plugin for WooCommerce Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks

CVE-2022-0633
UpdraftPlus WordPress Backup Plugin (Free) Web Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-863 2 PoCs

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

CVE-2022-1265
BulletProof Security Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-2372
YaySMTP – Simple WP SMTP Mail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0163
Smart Forms – when you need more than just a contact form Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-862 1 PoC

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.

CVE-2022-1645
Amazon Link Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-1905
Events Made Easy Web Database Windows
N/A
UNKNOWN
EPSS
23.8%
2022 CWE-89 1 PoC

The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2022-0627
Amelia – Events & Appointments Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-2350
Disable User Login Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.

CVE-2022-1761
Peter’s Collaboration E-mails Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.

CVE-2022-23342
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.

CVE-2022-26184
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

CVE-2022-0234
WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2022 CWE-79 1 PoC

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-0600
Conference Scheduler Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-0200
Themify Portfolio Post Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting