2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1392HIGH7.5The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include state...
CVE-2022-1391CRITICAL9.8The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in requ...
CVE-2022-1390CRITICAL9.8The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which...
CVE-2022-1228MEDIUM4.8The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" ...
CVE-2022-1156MEDIUM4.8The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high priv...
CVE-2022-1153MEDIUM4.8The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in v...
CVE-2022-1152MEDIUM5.4The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in ...
CVE-2022-1094MEDIUM4.8The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high p...
CVE-2022-1092MEDIUM4.3The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export...
CVE-2022-1027MEDIUM4.8The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the...
CVE-2022-0953MEDIUM6.1The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUER...
CVE-2022-0876MEDIUM4.8The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high p...
CVE-2022-0782CRITICAL9.8The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in...
CVE-2022-0769CRITICAL9.8The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it...
CVE-2022-0693CRITICAL9.8The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_...
CVE-2022-0657CRITICAL9.8The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validat...
CVE-2022-0656HIGH7.5The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url...
CVE-2022-0634MEDIUM4.3The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, ...
CVE-2022-0541CRITICAL9.8The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a...
CVE-2022-0398MEDIUM5.4The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks ...
CVE-2022-0363MEDIUM4.3The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-ex...
CVE-2022-0287MEDIUM4.3The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX...
CVE-2022-29078CRITICAL9.8The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[...
CVE-2022-28094MEDIUM6.1SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability vi...
CVE-2022-28093CRITICAL9.8SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which al...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now