2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1995MEDIUM4.8The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to maliciou...
CVE-2022-1994MEDIUM4.8The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its ...
CVE-2022-1990MEDIUM4.8The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow...
CVE-2022-1971MEDIUM4.8The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which c...
CVE-2022-1964MEDIUM5.4The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a ...
CVE-2022-1960MEDIUM4.3The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow a...
CVE-2022-1916MEDIUM6.1The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1...
CVE-2022-1914MEDIUM4.3The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could...
CVE-2022-1913MEDIUM4.3The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which coul...
CVE-2022-1904MEDIUM6.1The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputti...
CVE-2022-1885MEDIUM4.3The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its setting...
CVE-2022-1847MEDIUM4.3The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which cou...
CVE-2022-1846MEDIUM4.3The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which c...
CVE-2022-1845MEDIUM4.3The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attack...
CVE-2022-1844MEDIUM4.3The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could all...
CVE-2022-1843MEDIUM6.5The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to...
CVE-2022-1842MEDIUM4.3The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, whic...
CVE-2022-1776MEDIUM5.4The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape so...
CVE-2022-1653MEDIUM4.3The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints ...
CVE-2022-1627MEDIUM4.3The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which co...
CVE-2022-1625MEDIUM4.3The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding...
CVE-2022-1593MEDIUM6.1The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its setti...
CVE-2022-1573MEDIUM4.3The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could all...
CVE-2022-1470MEDIUM6.1The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before...
CVE-2022-1327MEDIUM4.8The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now