CVE-2022-2190 The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter, which could lead to Reflected Cross-Site Scripting in old browsers.
when a malicious user sends a request to a site with this plugin installed and receives a response with a maliciously crafted request_uri value.
CVE-2022-3366 The PublishPress Capabilities plugin before 2.5.2 unserializes imported files, which could lead to PHP object injection attacks by administrators.
This issue has been fixed in version 2.6.1 of both plugins.
PublishPress Capabilities Pro WordPress plugin before 2.6.1 uses an insecure
CVE-2022-3771 - Critical Unrestricted File Upload in easyii CMS (VDB-212501) – Explained
In late 2022, a high-impact vulnerability surfaced in easyii CMS. Labeled as CVE-2022-3771 (also known as VDB-212501), it enables attackers to
CVE-2022-40488 - How ProcessWire v3..200’s CSRF Flaw Can Expose Your Site (With an Example Exploit)
ProcessWire, a popular open source CMS (Content Management System) written in PHP, aims to make website development easy, secure, and robust. However, security vulnerabilities sometimes
CVE-2022-40487 - Unpacking the ProcessWire v3..200 Search XSS Vulnerabilities
ProcessWire is a popular open-source PHP content management system (CMS) used by thousands of websites, prized for its flexibility and lightweight design. However, even
Episode
00:00:00
00:00:00