LiveActive security incident?Get immediate response
CVE archive

March 2022

Browse CVE records published in March 2022, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1929 matching CVEs · Page 4 of 39.

Medium · CVSS 4.1

CVE-2022-25612: WordPress Simple Event Planner plugin <= 1.5.4 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities

Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &custom[organiser_email], &custom[organiser_contact].

Published Mar 25, 2022 · Updated Apr 28, 2026

Critical · CVSS 9.8

CVE-2022-0888: Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0

Published Mar 23, 2022 · Updated Apr 8, 2026

High · CVSS 7.2

CVE-2022-0889: Ninja Forms - File Uploads Extension <= 3.3.12 - Reflected Cross-Site Scripting

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.

Published Mar 23, 2022 · Updated Apr 8, 2026

High · CVSS 7.2

CVE-2022-0834: Amelia <= 1.0.46 - Stored Cross Site Scripting via lastName

The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user accesses the booking calendar with the date the attacker has injected the malicious payload into. This affects versions up to and including 1.0.46.

Published Mar 23, 2022 · Updated Apr 8, 2026

Medium · CVSS 6.4

CVE-2022-0750: Photoswipe Masonry Gallery <= 1.2.14 Stored Cross-Site Scripting

The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the thumbnail_width, thumbnail_height, max_image_width, and max_image_height parameters found in the ~/photoswipe-masonry.php file which allows authenticated attackers to inject arbitrary web scripts into galleries created by the plugin and on the PhotoSwipe Options page. This affects versions up to and including 1.2.14.

Published Mar 23, 2022 · Updated Apr 8, 2026

Medium · CVSS 4.3

CVE-2022-4932: Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure

The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions and above to retrieve back-up paths that can subsequently be used to download the back-up.

Published Mar 7, 2023 · Updated Apr 8, 2026

Medium · CVSS 5

CVE-2022-4862: XSS vulnerability in M-Files Web

Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.

Published Mar 6, 2023 · Updated Feb 23, 2026

Medium · CVSS 6.5

CVE-2022-3284: Insecure way of passing a download key

Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.

Published Mar 6, 2023 · Updated Feb 23, 2026