13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-37259
The Ultimate WordPress Toolkit – WP Extended Web Windows ⚡ nuclei
7.1
HIGH
EPSS
11.7%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through <= 2.4.7.

CVE-2024-3111
Interactive Content Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to Stored Cross-Site Scripting issues

CVE-2024-13352
Legull Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.8%
2024 1 PoC

The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13094
WP Triggers Lite Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.6%
2024 1 PoC

The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-5472
WP QuickLaTeX Web Windows
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5715
wp-eMember Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13056
Dyn Business Panel Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13624
WPMovieLibrary Web Windows ⚡ nuclei
7.1
HIGH
EPSS
1.5%
2024 1 PoC

The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-1983
Simple Ajax Chat Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.

CVE-2024-3903
Add Custom CSS and JS Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in as author and above add Stored XSS payloads via a CSRF attack

CVE-2024-29792
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Web ⚡ nuclei
7.1
HIGH
EPSS
14.4%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.93.

CVE-2024-28804
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.

CVE-2024-13885
WP e-Customers Beta Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-10483
Simple:Press Forum Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-13878
SpotBot Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13836
WP Login Control Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13877
Passbeemedia Web Push Notification Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-10152
Simple Certain Time to Show Content Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.6%
2024 1 PoC

The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-33526
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2024 1 PoC

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.

CVE-2024-7600
Unified SecOps Platform Web
7.1
HIGH
EPSS
3.6%
2024 CWE-22 1 PoC

Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of root. Was ZDI-CAN-25025.