CVE-2022-2219

The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:brizy:unyson:*:*:*:*:*:wordpress:*:*

History

29 Jul 2022, 16:09

Type Values Removed Values Added
First Time Brizy unyson
Brizy
CPE cpe:2.3:a:unyson_project:unyson:*:*:*:*:*:wordpress:*:* cpe:2.3:a:brizy:unyson:*:*:*:*:*:wordpress:*:*

29 Jul 2022, 15:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
References (MISC) https://wpscan.com/vulnerability/1240797c-7f45-4c36-83f0-501c544ce76a - (MISC) https://wpscan.com/vulnerability/1240797c-7f45-4c36-83f0-501c544ce76a - Exploit, Third Party Advisory
CPE cpe:2.3:a:unyson_project:unyson:*:*:*:*:*:wordpress:*:*
First Time Unyson Project
Unyson Project unyson

25 Jul 2022, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-25 13:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-2219

Mitre link : CVE-2022-2219

CVE.ORG link : CVE-2022-2219


JSON object : View

Products Affected

brizy

  • unyson
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')