Latest CVE Feed
-
6.5
MEDIUMCVE-2022-1570
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.... Read more
Affected Products : files_download_delay- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1569
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin... Read more
Affected Products : drag_\&_drop_builder- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1568
The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : team_members- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1566
The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by... Read more
Affected Products : quotes_llama- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-1565
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator leve... Read more
Affected Products : wp_all_import- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1564
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : form_maker- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1562
The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads... Read more
Affected Products : enable_svg- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1561
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulner... Read more
- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1560
The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, howev... Read more
Affected Products : amministrazione_aperta- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1559
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed... Read more
Affected Products : clipr- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1558
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed... Read more
Affected Products : curtain- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1557
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as ... Read more
Affected Products : uleak-security-dashboard- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1556
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection... Read more
Affected Products : stafflist- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1555
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1554
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.... Read more
Affected Products : scout- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1553
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website... Read more
Affected Products : publify- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1552
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands ac... Read more
Affected Products : postgresql- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1551
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.... Read more
Affected Products : sp_project_\&_document_manager- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1549
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.... Read more
Affected Products : wp_athletics- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1548
Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.... Read more
Affected Products : playbooks- Published: May. 03, 2022
- Modified: Nov. 21, 2024