Total
4402 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-1329 | 1 Elementor | 1 Website Builder | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2. | |||||
| CVE-2022-1273 | 1 Importwp | 1 Import Wp | 2026-06-17 | 6.5 MEDIUM | 7.2 HIGH |
| The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE | |||||
| CVE-2022-1206 | 2026-06-17 | N/A | 7.2 HIGH | ||
| The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present. | |||||
| CVE-2022-1103 | 1 Advanced Uploader Project | 1 Advanced Uploader | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE | |||||
| CVE-2022-1045 | 1 Trudesk Project | 1 Trudesk | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0. | |||||
| CVE-2022-1034 | 1 Showdoc | 1 Showdoc | 2026-06-17 | 6.5 MEDIUM | 7.2 HIGH |
| There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4. | |||||
| CVE-2022-1033 | 1 Craterapp | 1 Crater | 2026-06-17 | 6.5 MEDIUM | 7.8 HIGH |
| Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | |||||
| CVE-2022-1008 | 1 Ocdi | 1 One Click Demo Import | 2026-06-17 | 6.5 MEDIUM | 7.2 HIGH |
| The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed | |||||
| CVE-2022-0962 | 1 Showdoc | 1 Showdoc | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. | |||||
| CVE-2022-0960 | 1 Showdoc | 1 Showdoc | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4. | |||||
| CVE-2022-0959 | 1 Pgadmin | 1 Pgadmin 4 | 2026-06-17 | 3.5 LOW | 6.5 MEDIUM |
| A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write. | |||||
| CVE-2022-0951 | 1 Showdoc | 1 Showdoc | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. | |||||
| CVE-2022-0950 | 1 Showdoc | 1 Showdoc | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4. | |||||
| CVE-2022-0945 | 1 Showdoc | 1 Showdoc | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4. | |||||
| CVE-2022-0930 | 1 Microweber | 1 Microweber | 2026-06-17 | 3.5 LOW | 4.8 MEDIUM |
| File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | |||||
| CVE-2022-0921 | 1 Microweber | 1 Microweber | 2026-06-17 | 6.5 MEDIUM | 6.7 MEDIUM |
| Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12. | |||||
| CVE-2022-0912 | 1 Microweber | 1 Microweber | 2026-06-17 | 3.5 LOW | 4.8 MEDIUM |
| Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11. | |||||
| CVE-2022-0888 | 1 Ninjaforms | 1 Ninja Forms File Uploads | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0 | |||||
| CVE-2022-0863 | 1 Wp Svg Icons Project | 1 Wp Svg Icons | 2026-06-17 | 6.5 MEDIUM | 7.2 HIGH |
| The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution. | |||||
| CVE-2022-0687 | 1 Tms-outsource | 1 Amelia | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role. | |||||
