Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The plugin does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2219.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-2341 | Simple Page Transition <= 1.4.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2340 | W-DALIL <= 2.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2299 | Allow SVG Files <= 1.1 - Author+ Stored Cross Site Scripting via SVG | |
| CVE-2022-2240 | Request a Quote <= 2.3.7 - CSV Injection | |
| CVE-2022-2239 | Request a Quote < 2.3.9 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2189 | WP Video Lightbox < 1.9.5 - Reflected Cross-Site Scripting | |
| CVE-2022-2115 | Popup Anything < 2.1.7 - Reflected Cross-Site Scripting | |
| CVE-2022-2072 | Name Directory < 1.25.3 - Reflected Cross-Site Scripting | |
| CVE-2022-2071 | Name Directory < 1.25.4 - Stored Cross-Site Scripting via CSRF | |
| CVE-2022-1551 | SP Project & Document Manager < 4.58 - Sensitive File Disclosure | |
| CVE-2022-1539 | Exports and Reports < 0.9.2 - Contributor+ CSV Injection | |
| CVE-2022-0899 | Header Footer Code Manager < 1.1.24 - Reflected Cross-Site Scripting | |
| CVE-2022-0594 | Shareaholic < 9.7.6 - Information Disclosure |
No comments yet