2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1772MEDIUM4.8The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is re...
CVE-2022-1765HIGH8.8The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image...
CVE-2022-1764MEDIUM5.4The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul...
CVE-2022-1763MEDIUM5.4Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows c...
CVE-2022-1762HIGH7.5The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origi...
CVE-2022-1761MEDIUM6.5The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This...
CVE-2022-1759MEDIUM5.4The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic...
CVE-2022-1758HIGH8.8The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settin...
CVE-2022-1756MEDIUM6.1The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it ...
CVE-2022-1724MEDIUM6.1The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting t...
CVE-2022-1710MEDIUM4.8The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fiel...
CVE-2022-1707MEDIUM6.1The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s para...
CVE-2022-1694MEDIUM6.5The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page...
CVE-2022-1656MEDIUM5.4Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to acces...
CVE-2022-1624MEDIUM6.5The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, wh...
CVE-2022-1612MEDIUM6.5The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which c...
CVE-2022-1608MEDIUM6.5The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, ...
CVE-2022-1605MEDIUM6.5The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could...
CVE-2022-1604MEDIUM6.1The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2022-1595MEDIUM5.3The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted reque...
CVE-2022-1594MEDIUM4.3The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh...
CVE-2022-1549MEDIUM5.4The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor do...
CVE-2022-1532MEDIUM6.1Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an at...
CVE-2022-1412HIGH7.5The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filen...
CVE-2022-1336MEDIUM4.8The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now