Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1772 1 Google Places Reviews Project 1 Google Places Reviews 2026-06-17 2.1 LOW 4.8 MEDIUM
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.
CVE-2022-1757 1 Pagebar Project 1 Pagebar 2026-06-17 3.5 LOW 5.4 MEDIUM
The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues
CVE-2022-1756 1 Thenewsletterplugin 1 Newsletter 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.
CVE-2022-1755 1 Benbodhi 1 Svg Support 2026-06-17 N/A 5.4 MEDIUM
The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks
CVE-2022-1750 1 Sticky Popup Project 1 Sticky Popup 2026-06-17 3.5 LOW 5.5 MEDIUM
The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ popup_title' parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin level capabilities and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This issue mostly affects sites where unfiltered_html has been disabled for administrators and on multi-site installations where unfiltered_html is disabled for administrators.
CVE-2022-1730 1 Diagrams 1 Drawio 2026-06-17 3.5 LOW 4.6 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.
CVE-2022-1726 1 Bootstrap-table 1 Bootstrap Table 2026-06-17 3.5 LOW 5.4 MEDIUM
Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.
CVE-2022-1724 1 Simple-membership-plugin 1 Simple Membership 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting
CVE-2022-1719 1 Trudesk Project 1 Trudesk 2026-06-17 N/A 5.4 MEDIUM
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page
CVE-2022-1717 1 Wp-experts 1 Custom Share Buttons With Floating Sidebar 2026-06-17 3.5 LOW 4.8 MEDIUM
The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
CVE-2022-1710 1 Dwbooster 1 Appointment Hour Booking 2026-06-17 3.5 LOW 4.8 MEDIUM
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
CVE-2022-1707 1 Gtm4wp 1 Google Tag Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1.15. The affected file is ~/public/frontend.php and this could be exploited by unauthenticated attackers.
CVE-2022-1682 1 Facturascripts 1 Facturascripts 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser
CVE-2022-1673 1 Greenwallet 1 Woocommerce Green Wallet Gateway 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter before outputting it to the page, leading to a Reflected Cross-Site Scripting vulnerability.
CVE-2022-1647 1 Ncrafts 1 Formcraft 2026-06-17 3.5 LOW 4.8 MEDIUM
The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-1646 1 Simple Real Estate Pack Project 1 Simple Real Estate Pack 2026-06-17 3.5 LOW 4.8 MEDIUM
The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
CVE-2022-1645 1 Amazon Link Project 1 Amazon Link 2026-06-17 3.5 LOW 4.8 MEDIUM
The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2022-1644 1 Call\&book Mobile Bar Project 1 Call\&book Mobile Bar 2026-06-17 3.5 LOW 4.8 MEDIUM
The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2022-1643 1 Birthdays Widget Project 1 Birthdays Widget 2026-06-17 3.5 LOW 4.8 MEDIUM
The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
CVE-2022-1628 1 Coleds 1 Simple Seo 2026-06-17 N/A 6.4 MEDIUM
The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions to inject arbitrary web scripts into posts/pages that execute whenever an administrator access the page.