2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1654HIGH8.8Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or cu...
CVE-2022-0209MEDIUM4.8The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them bac...
CVE-2022-31400MEDIUM4.8A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execu...
CVE-2022-31398MEDIUM4.8A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute...
CVE-2022-31041MEDIUM6.5Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the for...
CVE-2022-2067CRITICAL9.1SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
CVE-2022-2066MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06.
CVE-2022-2065MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository neorazorx/facturascripts prior to 2022.06.
CVE-2022-1985MEDIUM6.1The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and includi...
CVE-2022-1918HIGH8.8The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2022-1900HIGH8.8The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. Thi...
CVE-2022-1822MEDIUM6.1The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parame...
CVE-2022-1814MEDIUM4.8The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow h...
CVE-2022-1800HIGH7.2The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exp...
CVE-2022-1793MEDIUM4.3The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow a...
CVE-2022-1792MEDIUM5.4The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which c...
CVE-2022-1791HIGH8.1The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting...
CVE-2022-1790MEDIUM6.5The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, w...
CVE-2022-1788MEDIUM6.5Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks....
CVE-2022-1787MEDIUM5.4The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo...
CVE-2022-1781MEDIUM5.4The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a...
CVE-2022-1780MEDIUM5.4The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could ...
CVE-2022-1779HIGH8.1The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which...
CVE-2022-1777HIGH8.8The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to ...
CVE-2022-1773MEDIUM6.1The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an ad...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now