2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31041MEDIUM6.5Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the for...
CVE-2022-2066MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06.
CVE-2022-2065MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository neorazorx/facturascripts prior to 2022.06.
CVE-2022-1985MEDIUM6.1The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and includi...
CVE-2022-1822MEDIUM6.1The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parame...
CVE-2022-1814MEDIUM4.8The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow h...
CVE-2022-1793MEDIUM4.3The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow a...
CVE-2022-1792MEDIUM5.4The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which c...
CVE-2022-1790MEDIUM6.5The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, w...
CVE-2022-1788MEDIUM6.5Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks....
CVE-2022-1787MEDIUM5.4The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo...
CVE-2022-1781MEDIUM5.4The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a...
CVE-2022-1780MEDIUM5.4The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could ...
CVE-2022-1773MEDIUM6.1The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an ad...
CVE-2022-1772MEDIUM4.8The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is re...
CVE-2022-1764MEDIUM5.4The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul...
CVE-2022-1763MEDIUM5.4Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows c...
CVE-2022-1761MEDIUM6.5The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This...
CVE-2022-1759MEDIUM5.4The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic...
CVE-2022-1756MEDIUM6.1The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it ...
CVE-2022-1724MEDIUM6.1The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting t...
CVE-2022-1710MEDIUM4.8The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fiel...
CVE-2022-1707MEDIUM6.1The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s para...
CVE-2022-1694MEDIUM6.5The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page...
CVE-2022-1656MEDIUM5.4Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to acces...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now