2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4483MEDIUM5.4The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outp...
CVE-2022-4482MEDIUM5.4The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shor...
CVE-2022-4481MEDIUM5.4The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes be...
CVE-2022-4480MEDIUM5.4The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before ou...
CVE-2022-4478MEDIUM5.4The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before out...
CVE-2022-4477MEDIUM5.4The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode att...
CVE-2022-4476MEDIUM5.4The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes befor...
CVE-2022-4469MEDIUM5.4The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before...
CVE-2022-4465MEDIUM5.4The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before...
CVE-2022-4464MEDIUM5.4Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes befo...
CVE-2022-4460MEDIUM5.4The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attrib...
CVE-2022-4453MEDIUM5.4The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outp...
CVE-2022-4451MEDIUM5.4The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before o...
CVE-2022-4449MEDIUM5.4The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before...
CVE-2022-4447CRITICAL9.8The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL sta...
CVE-2022-4442MEDIUM4.8The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its s...
CVE-2022-4431MEDIUM5.4The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputtin...
CVE-2022-4330MEDIUM4.8The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-4327Rejected reason: This issue does not bear any security risk as it's only exploitable by users with administrator or supe...
CVE-2022-4320MEDIUM6.1The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting ...
CVE-2022-4309LOW3.1The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers t...
CVE-2022-4299MEDIUM4.8The Metricool WordPress plugin before 1.18 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2022-4295MEDIUM6.1The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back i...
CVE-2022-4199MEDIUM4.8The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2022-4101CRITICAL9.1The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now