Total CVEs

132,371

Critical Severity

2,837

High Severity

10,154

Last 7 Days

1,754
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,281 - 4,300 of 28,776 CVEs
CVE-2022-50966 MEDIUM - 6.1

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests ...

Vendor: uBidAuction
Product: uBidAuction
Published: May 10, 2026
Source: NVD
CVE-2022-50965 MEDIUM - 6.1

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests...

Vendor: uBidAuction
Product: uBidAuction
Published: May 10, 2026
Source: NVD
CVE-2022-50964 MEDIUM - 6.1

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via ...

Vendor: uBidAuction
Product: uBidAuction
Published: May 10, 2026
Source: NVD
CVE-2022-50963 MEDIUM - 6.1

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via...

Vendor: uBidAuction
Product: uBidAuction
Published: May 10, 2026
Source: NVD
CVE-2022-50962 MEDIUM - 6.1

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET reque...

Vendor: uBidAuction
Product: uBidAuction
Published: May 10, 2026
Source: NVD
CVE-2022-50961 MEDIUM - 6.4

WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings t...

Vendor: IP2Location
Product: IP2Location Country Blocker
Published: May 10, 2026
Source: NVD
CVE-2022-50960 MEDIUM - 6.1

WordPress International Sms For Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary Ja...

Vendor: Varun Sridharan
Product: International Sms For Contact Form
Published: May 10, 2026
Source: NVD
CVE-2022-50959 MEDIUM - 6.1

WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter t...

Vendor: wpdevart
Product: Contact Form Builder
Published: May 10, 2026
Source: NVD
CVE-2022-50958 MEDIUM - 6.1

WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter t...

Vendor: jetpack
Product: Jetpack
Published: May 10, 2026
Source: NVD
CVE-2022-50957 MEDIUM - 6.1

Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execu...

Vendor: avatar_uploader
Product: avatar_uploader
Published: May 10, 2026
Source: NVD
CVE-2022-50956 MEDIUM - 6.2

WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to ...

Vendor: amministrazione-aperta
Product: amministrazione-aperta
Published: May 10, 2026
Source: NVD
CVE-2022-50955 MEDIUM - 4.3

WordPress Plugin Curtain 1.0.2 contains a cross-site request forgery vulnerability that allows attackers to activate or deactivate site maintenance mode by crafting malicious requests. Attackers can trick authenticated administrators into submitting forged requests to the options-general.php page wi...

Vendor: curtain
Product: Curtain
Published: May 10, 2026
Source: NVD
CVE-2022-50954 MEDIUM - 6.2

WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tblight.php. Attackers can supply path traversal sequences through the controller GET parameter to includ...

Vendor: cab-fare-calculator
Product: cab-fare-calculator
Published: May 10, 2026
Source: NVD
CVE-2022-50949 MEDIUM - 6.4

WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized nom, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through t...

Vendor: A-J-Evolution
Product: Videos sync PDF
Published: May 10, 2026
Source: NVD
CVE-2022-50948 MEDIUM - 6.4

Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommo...

Vendor: Motopress
Product: Motopress Hotel Booking Lite
Published: May 10, 2026
Source: NVD
CVE-2022-50947 MEDIUM - 6.4

WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript payloads through the testi...

Vendor: RadiusTheme
Product: Testimonial Slider and Showcase
Published: May 10, 2026
Source: NVD
CVE-2022-50946 MEDIUM - 6.4

WordPress Plugin Netroics Blog Posts Grid 1.0 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject script payloads through the testimonial title ...

Vendor: netroics
Product: Netroics Blog Posts Grid
Published: May 10, 2026
Source: NVD
CVE-2022-50945 MEDIUM - 6.4

WordPress 3dady real-time web stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields vi...

Vendor: 3dady
Product: real-time web stats
Published: May 10, 2026
Source: NVD
CVE-2022-50944 HIGH - 8.8

Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can upload PHP files with embedded code to the admin posts.php endpoint with source=add_post parameter, and...

Vendor: MegaTKC
Product: Aero CMS
Published: May 10, 2026
Source: NVD
CVE-2022-50943 MEDIUM - 6.1

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users...

Vendor: Moodle
Product: Moodle LMS
Published: May 10, 2026
Source: NVD