2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1712MEDIUM4.3The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could ...
CVE-2022-1709MEDIUM4.3The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all...
CVE-2022-1695MEDIUM4.3The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, a...
CVE-2022-1691MEDIUM4.9The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using...
CVE-2022-1685MEDIUM4.9The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter bef...
CVE-2022-1673MEDIUM6.1The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter be...
CVE-2022-1647MEDIUM4.8The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users suc...
CVE-2022-1598MEDIUM5.3The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a RES...
CVE-2022-1597MEDIUM6.1The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape...
CVE-2022-1577MEDIUM5.4The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backu...
CVE-2022-1570MEDIUM6.5The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its set...
CVE-2022-1569MEDIUM4.8The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Wor...
CVE-2022-1541MEDIUM4.8The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow...
CVE-2022-1506MEDIUM5.4The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users...
CVE-2022-1469MEDIUM4.8The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high ...
CVE-2022-1424MEDIUM6.5The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker t...
CVE-2022-1422MEDIUM6.5The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an ...
CVE-2022-1421MEDIUM4.3The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in ad...
CVE-2022-1394MEDIUM4.8The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, whi...
CVE-2022-1241MEDIUM6.1The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile ...
CVE-2022-1005MEDIUM6.1The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back i...
CVE-2022-0779MEDIUM6.5The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX a...
CVE-2022-31470MEDIUM6.1An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12...
CVE-2022-30466MEDIUM6.5joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay.
CVE-2022-29620MEDIUM6.5FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOT...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now