Latest CVE Feed
-
4.8
MEDIUMCVE-2022-1558
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed... Read more
Affected Products : curtain- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1557
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as ... Read more
Affected Products : uleak-security-dashboard- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1556
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection... Read more
Affected Products : stafflist- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1555
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1554
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.... Read more
Affected Products : scout- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1553
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website... Read more
Affected Products : publify- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1552
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands ac... Read more
Affected Products : postgresql- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1551
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.... Read more
Affected Products : sp_project_\&_document_manager- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1549
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.... Read more
Affected Products : wp_athletics- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1548
Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.... Read more
Affected Products : playbooks- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1547
The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : check_\&_log_email- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1546
The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : woocommerce_-_product_importer- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1545
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.... Read more
Affected Products : gitlab- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2022-1544
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or ... Read more
Affected Products : yii-helpers- Published: May. 01, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-1543
Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.... Read more
Affected Products : scoold- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1542
The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.... Read more
Affected Products : hpb_dashboard- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1541
The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : video_slider- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1539
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlin... Read more
Affected Products : exports_and_reports- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1537
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalatio... Read more
Affected Products : grunt- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1536
A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site s... Read more
Affected Products : automad- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024