2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4351HIGH7.2The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a ...
CVE-2022-4340MEDIUM5.3The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in...
CVE-2022-4329MEDIUM6.1The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before out...
CVE-2022-4324HIGH7.2The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead t...
CVE-2022-4302HIGH7.2The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow hig...
CVE-2022-4298CRITICAL9.8The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user ...
CVE-2022-4297CRITICAL9.8The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a ...
CVE-2022-4260MEDIUM4.8The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2022-4256MEDIUM4.8The All-in-One Addons for Elementor WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, whi...
CVE-2022-4237HIGH8.8The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functi...
CVE-2022-4236MEDIUM6.5The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content ...
CVE-2022-4200MEDIUM4.8The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could all...
CVE-2022-4198MEDIUM4.8The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow ...
CVE-2022-4142MEDIUM4.8The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg...
CVE-2022-4140HIGH7.5The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content ...
CVE-2022-4119MEDIUM4.8The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, wh...
CVE-2022-4114MEDIUM5.4The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as ...
CVE-2022-4109LOW2.7The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal a...
CVE-2022-4099CRITICAL9.8The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using th...
CVE-2022-4059CRITICAL9.8The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it ...
CVE-2022-4057MEDIUM5.3The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs...
CVE-2022-4049CRITICAL9.8The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL stat...
CVE-2022-3994MEDIUM4.3The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, w...
CVE-2022-3936MEDIUM4.8The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow hig...
CVE-2022-3911HIGH8.8The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now