2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4351 | HIGH | 7.2 | 1.1% | Jan 2, 2023 | The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2022-4340 | MEDIUM | 5.3 | 0.7% | Jan 2, 2023 | The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in... |
| CVE-2022-4329 | MEDIUM | 6.1 | 0.5% | Jan 2, 2023 | The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before out... |
| CVE-2022-4324 | HIGH | 7.2 | 17.7% | Jan 2, 2023 | The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead t... |
| CVE-2022-4302 | HIGH | 7.2 | 17.7% | Jan 2, 2023 | The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow hig... |
| CVE-2022-4298 | CRITICAL | 9.8 | 1.8% | Jan 2, 2023 | The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user ... |
| CVE-2022-4297 | CRITICAL | 9.8 | 3.6% | Jan 2, 2023 | The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a ... |
| CVE-2022-4260 | MEDIUM | 4.8 | 0.9% | Jan 2, 2023 | The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2022-4256 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The All-in-One Addons for Elementor WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, whi... |
| CVE-2022-4237 | HIGH | 8.8 | 1.1% | Jan 2, 2023 | The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functi... |
| CVE-2022-4236 | MEDIUM | 6.5 | 0.8% | Jan 2, 2023 | The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content ... |
| CVE-2022-4200 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could all... |
| CVE-2022-4198 | MEDIUM | 4.8 | 0.6% | Jan 2, 2023 | The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2022-4142 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg... |
| CVE-2022-4140 | HIGH | 7.5 | 2.9% | Jan 2, 2023 | The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content ... |
| CVE-2022-4119 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, wh... |
| CVE-2022-4114 | MEDIUM | 5.4 | 0.5% | Jan 2, 2023 | The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as ... |
| CVE-2022-4109 | LOW | 2.7 | 0.7% | Jan 2, 2023 | The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal a... |
| CVE-2022-4099 | CRITICAL | 9.8 | 1.0% | Jan 2, 2023 | The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using th... |
| CVE-2022-4059 | CRITICAL | 9.8 | 4.8% | Jan 2, 2023 | The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it ... |
| CVE-2022-4057 | MEDIUM | 5.3 | 1.5% | Jan 2, 2023 | The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs... |
| CVE-2022-4049 | CRITICAL | 9.8 | 4.8% | Jan 2, 2023 | The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL stat... |
| CVE-2022-3994 | MEDIUM | 4.3 | 0.8% | Jan 2, 2023 | The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, w... |
| CVE-2022-3936 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow hig... |
| CVE-2022-3911 | HIGH | 8.8 | 0.5% | Jan 2, 2023 | The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensu... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now