Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | CDI – Collect and Deliver Interface for Woocommerce | 5.1.9 ~ 5.1.9 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress CDI plugin prior to 5.1.9 contains a cross-site scripting vulnerability. The plugin does not sanitize and escape a parameter before outputting it back in the response of an AJAX action. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1933.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-2146 | Import CSV Files <= 1.0 - Reflected Cross-Site Scripting | |
| CVE-2021-24655 | WP User Manager < 2.6.3 - Arbitrary User Password Reset to Account Compromise | |
| CVE-2022-1672 | Insights from Google PageSpeed < 4.0.7 - Multiple CSRF | |
| CVE-2022-2090 | Woo Discount Rules < 2.4.2 - Reflected Cross-Site Scripting | |
| CVE-2022-2099 | WooCommerce < 6.6.0 - Admin+ Stored HTML Injection | |
| CVE-2022-2100 | Page Generator Plugin < 1.6.5 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2114 | Data Tables Generator by Supsystic < 1.10.20 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2118 | 404s < 3.5.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2133 | OAuth Single Sign On < 6.22.6 - Authentication Bypass | |
| CVE-2022-2144 | Jquery Validation For Contact Form 7 < 5.3 - Arbitrary Options Update via CSRF | |
| CVE-2022-2222 | Download Monitor < 4.5.91 - Admin+ Arbitrary File Download | |
| CVE-2022-2148 | LinkedIn Company Updates <= 1.5.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2149 | Very Simple Breadcrumb <= 1.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2151 | Best Contact Management Software <= 3.7.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2168 | Download Manager < 3.2.44 - Reflected Cross-Site Scripting | |
| CVE-2022-2169 | Loading Page with Loading Screen < 1.0.83 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2173 | Advanced Database Cleaner < 3.1.1 - Reflected Cross-Site Scripting | |
| CVE-2022-2186 | Simple Post Notes < 1.7.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2187 | Contact Form 7 Captcha < 0.1.2 - Reflected Cross-Site Scripting | |
| CVE-2022-2194 | Accept Stripe Payments < 2.0.64 - Admin+ Stored Cross-Site Scripting |
No comments yet