Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Header Footer Code Manager | 1.1.24 ~ 1.1.24 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0899.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-2341 | Simple Page Transition <= 1.4.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2340 | W-DALIL <= 2.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2299 | Allow SVG Files <= 1.1 - Author+ Stored Cross Site Scripting via SVG | |
| CVE-2022-2240 | Request a Quote <= 2.3.7 - CSV Injection | |
| CVE-2022-2239 | Request a Quote < 2.3.9 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2219 | Unyson < 2.7.27 - Reflected Cross-Site Scripting | |
| CVE-2022-2189 | WP Video Lightbox < 1.9.5 - Reflected Cross-Site Scripting | |
| CVE-2022-2115 | Popup Anything < 2.1.7 - Reflected Cross-Site Scripting | |
| CVE-2022-2072 | Name Directory < 1.25.3 - Reflected Cross-Site Scripting | |
| CVE-2022-2071 | Name Directory < 1.25.4 - Stored Cross-Site Scripting via CSRF | |
| CVE-2022-1551 | SP Project & Document Manager < 4.58 - Sensitive File Disclosure | |
| CVE-2022-1539 | Exports and Reports < 0.9.2 - Contributor+ CSV Injection | |
| CVE-2022-0594 | Shareaholic < 9.7.6 - Information Disclosure |
No comments yet