Total
3867 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-21809 | 1 Inhandnetworks | 2 Inrouter302, Inrouter302 Firmware | 2024-11-21 | 5.5 MEDIUM | 8.1 HIGH |
|
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.
|
|||||
| CVE-2022-1939 | 1 Allow Svg Files Project | 1 Allow Svg Files | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to
|
|||||
| CVE-2022-1837 | 1 Home Clean Services Management System Project | 1 Home Clean Services Management System | 2024-11-21 | 6.5 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.
|
|||||
| CVE-2022-1811 | 1 Publify Project | 1 Publify | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.
|
|||||
| CVE-2022-1752 | 1 Trudesk Project | 1 Trudesk | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
|
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
|
|||||
| CVE-2022-1565 | 1 Wpallimport | 1 Wp All Import | 2024-11-21 | N/A | 7.2 HIGH |
|
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.
|
|||||
| CVE-2022-1519 | 1 Illumina | 8 Iseq 100, Local Run Manager, Miniseq and 5 more | 2024-11-21 | 10.0 HIGH | 10.0 CRITICAL |
|
LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executable code that allows for a remote code exploit.
|
|||||
| CVE-2022-1411 | 1 Yetiforce | 1 Yetiforce Customer Relationship Management | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
|
|||||
| CVE-2022-1409 | 1 Vikwp | 1 Hotel Booking Engine \& Pms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code
|
|||||
| CVE-2022-1345 | 1 Organizr | 1 Organizr | 2024-11-21 | 3.5 LOW | 9.0 CRITICAL |
|
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
|
|||||
| CVE-2022-1329 | 1 Elementor | 1 Website Builder | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
|
|||||
| CVE-2022-1273 | 1 Importwp | 1 Import Wp | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE
|
|||||
| CVE-2022-1103 | 1 Advanced Uploader Project | 1 Advanced Uploader | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE
|
|||||
| CVE-2022-1045 | 1 Trudesk Project | 1 Trudesk | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
|
|||||
| CVE-2022-1034 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.
|
|||||
| CVE-2022-1033 | 1 Craterapp | 1 Crater | 2024-11-21 | 6.5 MEDIUM | 7.8 HIGH |
|
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
|
|||||
| CVE-2022-1008 | 1 Ocdi | 1 One Click Demo Import | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
|
|||||
| CVE-2022-0962 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.
|
|||||
| CVE-2022-0960 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
|
|||||
| CVE-2022-0951 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.
|
|||||
| CVE-2022-0950 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.
|
|||||
| CVE-2022-0945 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.
|
|||||
| CVE-2022-0930 | 1 Microweber | 1 Microweber | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
|
|||||
| CVE-2022-0921 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.5 MEDIUM | 6.7 MEDIUM |
|
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
|
|||||
| CVE-2022-0912 | 1 Microweber | 1 Microweber | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.
|
|||||
| CVE-2022-0888 | 1 Ninjaforms | 1 Ninja Forms File Uploads | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
|
|||||
| CVE-2022-0863 | 1 Wp Svg Icons Project | 1 Wp Svg Icons | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
|
|||||
| CVE-2022-0687 | 1 Tms-outsource | 1 Amelia | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.
|
|||||
| CVE-2022-0537 | 1 Mappresspro | 1 Mappress | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is added. No validation is performed on the content of the file, triggering an RCE vulnerability by uploading a web shell. Further the name parameter is not sanitized, allowing the pa ...
Show More |
|||||
| CVE-2022-0499 | 1 Sermon Browser Project | 1 Sermon Browser | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.
|
|||||
| CVE-2022-0472 | 1 Laracom Project | 1 Laracom | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.
|
|||||
| CVE-2022-0440 | 1 Catchplugins | 1 Catch Themes Demo Import | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)
|
|||||
| CVE-2022-0415 | 1 Gogs | 1 Gogs | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
|
|||||
| CVE-2022-0409 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.
|
|||||
| CVE-2022-0403 | 1 Wpjos | 1 Library File Manager | 2024-11-21 | 5.5 MEDIUM | 8.1 HIGH |
|
The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files ...
Show More |
|||||
| CVE-2022-0263 | 1 Pimcore | 1 Pimcore | 2024-11-21 | 4.6 MEDIUM | 7.8 HIGH |
|
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
|
|||||
| CVE-2022-0242 | 1 Craterapp | 1 Crater | 2024-11-21 | 6.0 MEDIUM | 7.2 HIGH |
|
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.
|
|||||
| CVE-2021-4436 | 1 Wp3dprinting | 1 3dprint Lite | 2024-11-21 | N/A | 9.8 CRITICAL |
|
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.
|
|||||
| CVE-2021-4382 | 1 Recently Project | 1 Recently | 2024-11-21 | N/A | 8.8 HIGH |
|
The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function in versions up to, and including, 3.0.4. This makes it possible for authenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
|
|||||
| CVE-2021-4354 | 1 Magazine3 | 1 Pwa For Wp \& Amp | 2024-11-21 | N/A | 8.8 HIGH |
|
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
|
|||||