Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection | 6.930 ~ 6.930 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Stop Bad Bots plugin before 6.930 contains a SQL injection vulnerability. The plugin does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0949.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-0828 | Download Manager < 3.2.39 - Unauthenticated brute force of files master key | |
| CVE-2021-24986 | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword | |
| CVE-2021-24987 | Super Socializer < 7.13.30 - Reflected Cross-Site Scripting | |
| CVE-2021-25090 | GridKit Portfolio < 2.1.0 - Subscriber+ Stored Cross-Site Scripting | |
| CVE-2022-0246 | iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip | |
| CVE-2022-0271 | LearnPress < 4.1.6 - Reflected Cross-Site Scripting | |
| CVE-2022-0314 | Nimble Page Builder < 3.2.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0447 | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types | |
| CVE-2022-0471 | Favicon by RealFaviconGenerator < 1.3.23 - Reflected Cross-Site Scripting | |
| CVE-2022-0531 | WPvivid Backup and Migration Plugin < 0.9.70 - Reflected Cross-Site Scripting | |
| CVE-2022-0728 | Easy Smooth Scroll Links < 2.23.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1023 | Podcast Importer SecondLine < 1.3.8 - Admin+ SQLi | |
| CVE-2022-0840 | Easy Social Icons < 3.2.1 - Admin+ Stored Cross-Site Scripting in add icon | |
| CVE-2022-0892 | Export All URLs < 4.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0914 | Export All URLs < 4.3 - Private/Draft Post/Page Title Disclosure via CSRF | |
| CVE-2022-0919 | Salon booking system < 7.6.3 - Unauthenticated Sensitive Data Disclosure | |
| CVE-2022-0920 | Salon booking system < 7.6.3 - Customer+ Bookings/Customers Data Disclosure | |
| CVE-2022-0969 | Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0989 | NS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality | |
| CVE-2022-1006 | Advanced Booking Calendar < 1.7.1 - Admin+ SQLi |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet