Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-0515 | 1 Craterapp | 1 Crater | 2022-03-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | |||||
CVE-2022-26555 | 1 Eova | 1 Eova | 2022-03-28 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box. | |||||
CVE-2022-26247 | 1 Teamwork Management System Project | 1 Teamwork Management System | 2022-03-28 | 4.3 MEDIUM | 5.9 MEDIUM |
TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password. | |||||
CVE-2022-0681 | 1 Simple-membership-plugin | 1 Simple Membership | 2022-03-28 | 4.3 MEDIUM | 6.5 MEDIUM |
The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack | |||||
CVE-2022-26246 | 1 Tms Project | 1 Tms | 2022-03-28 | 4.3 MEDIUM | 6.1 MEDIUM |
TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate. | |||||
CVE-2022-0640 | 1 Wpdevart | 1 Pricing Table Builder | 2022-03-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |||||
CVE-2022-25464 | 1 Html-js | 1 Doracms | 2022-03-28 | 3.5 LOW | 4.8 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
CVE-2022-24125 | 1 Fromsoftware | 1 Dark Souls Iii | 2022-03-28 | 6.5 MEDIUM | 8.8 HIGH |
The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToPlayers request. For example, ability to send a push message to hundreds of thousands of machines is only restricted on the client side, and can thus be bypassed with a modified client. | |||||
CVE-2022-0628 | 1 Accesspressthemes | 1 Ap Mega Menu | 2022-03-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |||||
CVE-2022-0627 | 1 Tms-outsource | 1 Amelia | 2022-03-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |||||
CVE-2022-0616 | 1 Tms-outsource | 1 Amelia | 2022-03-28 | 4.3 MEDIUM | 4.3 MEDIUM |
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack | |||||
CVE-2022-0591 | 1 Subtlewebinc | 1 Formcraft3 | 2022-03-28 | 6.4 MEDIUM | 9.1 CRITICAL |
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users | |||||
CVE-2022-0991 | 1 Admidio | 1 Admidio | 2022-03-28 | 6.4 MEDIUM | 7.1 HIGH |
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9. | |||||
CVE-2022-0423 | 1 3dflipbook | 1 3d Flipbook | 2022-03-28 | 3.5 LOW | 5.4 MEDIUM |
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook. | |||||
CVE-2022-0590 | 1 Ait-pro | 1 Bulletproof Security | 2022-03-28 | 3.5 LOW | 4.8 MEDIUM |
The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-0364 | 1 Webnus | 1 Modern Events Calendar Lite | 2022-03-28 | 3.5 LOW | 5.4 MEDIUM |
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |||||
CVE-2022-0229 | 1 Miniorange | 1 Google Authenticator | 2022-03-28 | 5.8 MEDIUM | 8.1 HIGH |
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable. | |||||
CVE-2022-0694 | 1 Elbtide | 1 Advanced Booking Calendar | 2022-03-28 | 7.5 HIGH | 9.8 CRITICAL |
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection | |||||
CVE-2021-25019 | 1 Squirrly | 1 Seo | 2022-03-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-26267 | 1 Piwigo | 1 Piwigo | 2022-03-28 | 5.0 MEDIUM | 7.5 HIGH |
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php. |