2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4627MEDIUM5.4The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputti...
CVE-2022-4625MEDIUM5.4The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before...
CVE-2022-4624MEDIUM5.4The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before ou...
CVE-2022-4576MEDIUM5.4The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attribute...
CVE-2022-4570MEDIUM5.4The Top 10 WordPress plugin before 3.2.3 does not validate and escape some of its Block attributes before outputting the...
CVE-2022-4548MEDIUM6.5The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place wh...
CVE-2022-4545MEDIUM5.4The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting ...
CVE-2022-4542MEDIUM5.4The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes ...
CVE-2022-4509MEDIUM5.4The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before...
CVE-2022-4485MEDIUM5.4The Page-list WordPress plugin before 5.3 does not validate and escape some of its shortcode attributes before outputtin...
CVE-2022-4475MEDIUM5.4The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4474MEDIUM5.4The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4467MEDIUM5.4The Search & Filter WordPress plugin before 1.2.16 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4443MEDIUM6.5The BruteBank WordPress plugin before 1.9 does not have CSRF check in place when updating its settings, which could allo...
CVE-2022-4383CRITICAL9.8The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in...
CVE-2022-4346MEDIUM5.3The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used ...
CVE-2022-4323HIGH7.2The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high...
CVE-2022-4307MEDIUM6.1The پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenti...
CVE-2022-4305CRITICAL9.8The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to...
CVE-2022-4303HIGH7.5The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers ...
CVE-2022-4230HIGH8.8The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to p...
CVE-2022-4017HIGH8.8The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, B...
CVE-2022-47065HIGH8.8TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow...
CVE-2022-41505MEDIUM6.4An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by c...
CVE-2022-3811MEDIUM4.8The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now