Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2395 1 Weformspro 1 Weforms 2026-06-17 N/A 4.8 MEDIUM
The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2391 1 Wpzoom 1 Inspiro Pro 2026-06-17 N/A 5.4 MEDIUM
The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.
CVE-2022-2386 1 Automattic 1 Crowdsignal Dashboard 2026-06-17 N/A 6.1 MEDIUM
The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2384 1 Supsystic 1 Digital Publications By Supsystic 2026-06-17 N/A 4.8 MEDIUM
The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2383 1 Slickremix 1 Feed Them Social 2026-06-17 N/A 6.1 MEDIUM
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2378 1 Easy Student Results Project 1 Easy Student Results 2026-06-17 N/A 6.1 MEDIUM
The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2375 1 Okapitech 1 Wp Sticky Button 2026-06-17 N/A 5.4 MEDIUM
The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues
CVE-2022-2374 1 Nsqua 1 Simply Schedule Appointments 2026-06-17 N/A 4.8 MEDIUM
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2372 1 Yaycommerce 1 Yaysmtp 2026-06-17 N/A 4.8 MEDIUM
The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2371 1 Yaycommerce 1 Yaysmtp 2026-06-17 N/A 5.4 MEDIUM
The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.
CVE-2022-2365 1 Trilium Project 1 Trilium 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.
CVE-2022-2364 1 Simple Parking Management System Project 1 Simple Parking Management System 2026-06-17 3.5 LOW 3.5 LOW
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Parking Management System 1.0. This affects an unknown part of the file /ci_spms/admin/category. The manipulation of the argument vehicle_type with the input "><script>alert("XSS")</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-2363 1 Simple Parking Management System Project 1 Simple Parking Management System 2026-06-17 3.5 LOW 3.5 LOW
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Parking Management System 1.0. Affected by this issue is some unknown functionality of the file /ci_spms/admin/search/searching/. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-2362 1 W3eden 1 Download Manager 2026-06-17 N/A 7.5 HIGH
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.
CVE-2022-2361 1 Quadlayers 1 Wp Social Chat 2026-06-17 N/A 4.8 MEDIUM
The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.
CVE-2022-2351 1 Wpexperts 1 Post Smtp 2026-06-17 N/A 4.8 MEDIUM
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.
CVE-2022-2342 1 Getoutline 1 Outline 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.
CVE-2022-2341 1 Simple Page Transition Project 1 Simple Page Transition 2026-06-17 N/A 4.8 MEDIUM
The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2340 1 W-dalil Project 1 W-dalil 2026-06-17 N/A 4.8 MEDIUM
The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2328 1 Flexi Quote Rotator Project 1 Flexi Quote Rotator 2026-06-17 N/A 4.8 MEDIUM
The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.