13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-7197
Marketing Twitter Bot Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-37988
Contact Form Generator Web ⚡ nuclei
7.1
HIGH
EPSS
21.8%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.

CVE-2023-30868
CMS Tree Page View Web ⚡ nuclei
7.1
HIGH
EPSS
54.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.

CVE-2023-32961
Zotpress Web
7.1
HIGH
EPSS
4.7%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions.

CVE-2023-2591
nilsteampassnet/teampass Web
7.1
HIGH
EPSS
0.3%
2023 CWE-79 2 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVE-2024-34469
Software Genérico Web
7.1
HIGH
EPSS
1.2%
2024 1 PoC

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

CVE-2024-13891
Schedule Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12400
tourmaster Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2024-13631
Om Stripe Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6529
Ultimate Classified Listings Web Windows
7.1
HIGH
EPSS
52.4%
2024 2 PoCs

The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-7601
Unified SecOps Platform Web
7.1
HIGH
EPSS
1.4%
2024 CWE-22 1 PoC

Logsign Unified SecOps Platform Directory data_export_delete_all Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of root. W

CVE-2024-37261
WP-Lister Lite for Amazon Web ⚡ nuclei
7.1
HIGH
EPSS
17.5%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <= 2.6.16.

CVE-2024-47374
LiteSpeed Cache Web ⚡ nuclei
7.1
HIGH
EPSS
26.5%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.

CVE-2024-13057
Dyn Business Panel Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-38694
Moloni Web
7.1
HIGH
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Moloni allows Reflected XSS.This issue affects Moloni: from n/a through 4.7.4.

CVE-2024-30194
Sunshine Photo Cart Web ⚡ nuclei
7.1
HIGH
EPSS
18.7%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.

CVE-2024-21285
Oracle Banking Liquidity Management Web Database
7.1
HIGH
EPSS
1.1%
2024 1 PoC

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).

CVE-2024-13862
S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) Web Cloud Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-27960
Email Subscription Popup Web
7.1
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Email Subscription Popup allows Stored XSS.This issue affects Email Subscription Popup: from n/a through 1.2.20.