Total
38071 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-1584 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim | |||||
CVE-2022-1582 | 1 Webfactoryltd | 1 External Links In New Window \/ New Tab | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible. | |||||
CVE-2022-1575 | 1 Diagrams | 1 Drawio | 2024-11-21 | 6.8 MEDIUM | 9.6 CRITICAL |
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app. | |||||
CVE-2022-1571 | 1 Facturascripts | 1 Facturascripts | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ... | |||||
CVE-2022-1569 | 1 Pieforms | 1 Drag \& Drop Builder | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed | |||||
CVE-2022-1568 | 1 Wpdarko | 1 Team Members | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |||||
CVE-2022-1566 | 1 Quotes Llama Project | 1 Quotes Llama | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by tricking an admin to import a malicious CSV file | |||||
CVE-2022-1564 | 1 10web | 1 Form Maker | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |||||
CVE-2022-1562 | 1 Room 34 Creative Services | 1 Enable Svg | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads | |||||
CVE-2022-1559 | 1 Clipr | 1 Clipr | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed | |||||
CVE-2022-1558 | 1 Curtain Project | 1 Curtain | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | |||||
CVE-2022-1557 | 1 Uleak-security-dashboard Project | 1 Uleak-security-dashboard | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks against admins viewing the settings | |||||
CVE-2022-1555 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie... | |||||
CVE-2022-1549 | 1 Wp Athletics Project | 1 Wp Athletics | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability. | |||||
CVE-2022-1547 | 1 Wpchill | 1 Check \& Log Email | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-1546 | 1 Visser | 1 Woocommerce - Product Importer | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-1542 | 1 Justsystems | 1 Hpb Dashboard | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |||||
CVE-2022-1541 | 1 Richweb | 1 Video Slider | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |||||
CVE-2022-1536 | 1 Automad | 1 Automad | 2024-11-21 | 3.5 LOW | 3.5 LOW |
A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used. | |||||
CVE-2022-1532 | 1 Themify | 1 Woocommerce Product Filter | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |