Export limit exceeded: 360000 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (360000 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-23981 | 1 Quadlayers | 1 Perfect Brands For Woocommerce | 2025-02-20 | 4.3 Medium |
| The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4). | ||||
| CVE-2022-23982 | 1 Quadlayers | 1 Perfect Brands For Woocommerce | 2025-02-20 | 4.3 Medium |
| The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure. | ||||
| CVE-2022-23983 | 1 Wp-buy | 1 Wp Content Copy Protection \& No Right Click | 2025-02-20 | 4.3 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress plugin (versions <= 3.4.4). | ||||
| CVE-2022-23984 | 1 Gvectors | 1 Wpdiscuz | 2025-02-20 | 3.7 Low |
| Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). | ||||
| CVE-2022-25599 | 1 Spiffyplugins | 1 Spiffy Calendar | 2025-02-20 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0). | ||||
| CVE-2021-26256 | 1 Ays-pro | 1 Survey Maker | 2025-02-20 | 4.7 Medium |
| Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6). | ||||
| CVE-2022-25601 | 2 Fedoraproject, Plugin-planet | 2 Fedora, Contact Form X | 2025-02-20 | 4.7 Medium |
| Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4). | ||||
| CVE-2022-25603 | 1 Maxfoundry | 1 Maxgalleria | 2025-02-20 | 4.8 Medium |
| Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5). | ||||
| CVE-2022-25604 | 1 Price Table Project | 1 Price Table | 2025-02-20 | 4.1 Medium |
| Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Price Table plugin (versions <= 0.2.2). | ||||
| CVE-2022-25602 | 1 Expresstech | 1 Responsive Menu | 2025-02-20 | 8.3 High |
| Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7). | ||||
| CVE-2022-25605 | 1 Wp-downloadmanager Project | 1 Wp-downloadmanager | 2025-02-20 | 4.8 Medium |
| Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url. | ||||
| CVE-2022-25607 | 1 Foliovision | 1 Fv Flowplayer Video Player | 2025-02-20 | 6.6 Medium |
| Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727). | ||||
| CVE-2022-25608 | 1 Yooslider | 1 Yoo Slider | 2025-02-20 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or delete action. | ||||
| CVE-2022-25609 | 1 Yooslider | 1 Yoo Slider | 2025-02-20 | 5.4 Medium |
| Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with contributor or higher user role to inject the malicious code. | ||||
| CVE-2022-25606 | 1 Wp-downloadmanager Project | 1 Wp-downloadmanager | 2025-02-20 | 4.8 Medium |
| Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories. | ||||
| CVE-2022-25610 | 1 Plugin-planet | 1 Simple Ajax Chat | 2025-02-20 | 3.4 Low |
| Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit. | ||||
| CVE-2022-25611 | 1 Presstigers | 1 Simple Event Planner | 2025-02-20 | 4.1 Medium |
| Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][]. | ||||
| CVE-2022-25612 | 1 Presstigers | 1 Simple Event Planner | 2025-02-20 | 4.1 Medium |
| Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &custom[organiser_email], &custom[organiser_contact]. | ||||
| CVE-2022-25618 | 1 Tms-outsource | 1 Wpdatatables Lite | 2025-02-20 | 3.4 Low |
| Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.1.27 | ||||
| CVE-2021-36851 | 1 Web-settler | 1 Testimonial Slider | 2025-02-20 | 4.1 Medium |
| Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color. | ||||