Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Caldera Forms – More Than Contact Forms | 1.9.7 ~ 1.9.7 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Caldera Forms WordPress plugin < 1.9.7 contains a reflected cross-site scripting caused by lack of validation and escaping of the cf-api parameter in responses, letting attackers execute arbitrary scripts in victim's browser, exploit requires attacker to craft a malicious request. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0879.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-1001 | WP Downgrade < 1.2.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1112 | Autolinks <= 1.0.1 - Stored Cross-Site Scripting via CSRF | |
| CVE-2022-1091 | Safe SVG < 1.9.10 - SVG Sanitisation Bypass | |
| CVE-2022-1090 | Good & Bad Comments <= 1.0.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1088 | Page Security & Membership <= 1.5.15 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1063 | Thank Me Later <= 3.3.4 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1054 | RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export | |
| CVE-2022-1037 | EXMAGE < 1.0.7 - Admin+ Blind SSRF | |
| CVE-2022-1020 | Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call | |
| CVE-2021-25120 | Easy Social Feed < 6.2.7 - Reflected Cross-Site Scripting | |
| CVE-2022-0994 | Hummingbird < 3.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0785 | Daily Prayer Time < 2022.03.01 - Unauthenticated SQLi | |
| CVE-2022-0780 | SearchIQ < 3.9 - Unauthenticated Stored XSS | |
| CVE-2022-0765 | Loco Translate < 2.6.1 - Authenticated Stored Cross-Site Scripting | |
| CVE-2022-0737 | Text Hover < 4.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0707 | Easy Digital Downloads < 2.11.6 - Arbitrary Payment Note Insertion via CSRF | |
| CVE-2022-0706 | Easy Digital Downloads < 2.11.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0661 | Ad Injection <= 1.2.0.19 - Admin+ Stored Cross-Site Scripting & RCE |
No comments yet