Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Find And Replace All Project Subscribe
Filtered by product Find And Replace All
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3850 1 Find And Replace All Project 1 Find And Replace All 2022-11-29 N/A 4.3 MEDIUM
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack
CVE-2022-2311 1 Find And Replace All Project 1 Find And Replace All 2022-11-29 N/A 6.1 MEDIUM
The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.