1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-1194
Mobile Events Manager Web Windows
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-1236 1 PoC

The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.

CVE-2022-3132
Goolytics – Simple Google Analytics Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0836
SEMA API Web Database Windows
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-89 1 PoC

The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users

CVE-2022-1598
WPQA Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
31.6%
2022 2 PoCs

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

CVE-2022-1005
WP Statistics Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

CVE-2022-0440
Catch Themes Demo Import Web Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-434 1 PoC

The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)

CVE-2022-0169
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.2%
2022 CWE-89 2 PoCs

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVE-2022-41184
SAP 3D Visual Enterprise Author Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-1910
Shortcodes and extra features for Phlox theme Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2022 CWE-79 1 PoC

The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-2090
Discount Rules for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting

CVE-2022-2375
WP Sticky Button – Click to Chat Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-79 1 PoC

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

CVE-2022-1327
Image Gallery – Grid Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-1933
CDI – Collect and Deliver Interface for Woocommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.5%
2022 CWE-79 1 PoC

The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVE-2022-2710
Scroll To Top Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Scroll To Top WordPress plugin before 1.4.1 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1686
Five Minute Webshop Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection

CVE-2022-0840
Easy Social Icons Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.

CVE-2022-1104
Popup Maker – Popup for opt-ins, lead gen, & more Web Windows
N/A
UNKNOWN
EPSS
13.5%
2022 CWE-79 1 PoC

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-2391
Inspiro PRO Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.

CVE-2022-0879
Caldera Forms – More Than Contact Forms Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-1913
Add Post URL Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping