13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4152
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.9%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-3879
Car Dealer (Dealership) and Vehicle sales WordPress Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-41296
Db2U Web
6.5
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.

CVE-2022-45170
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.

CVE-2022-4024
Registration Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CVE-2022-45180
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).

CVE-2022-45130
Software Genérico Web
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.

CVE-2022-1224
phpipam/phpipam Web
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

CVE-2022-3082
miniOrange Discord Integration Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

CVE-2022-35136
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.

CVE-2025-70899
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.

CVE-2026-33523
Apache HTTP Server Web
6.5
MEDIUM
EPSS
0.2%
2026 CWE-443 1 PoC

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2025-70091
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter.

CVE-2025-70094
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.

CVE-2026-0737
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.4
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-31807
siyuan Web ⚡ nuclei
6.4
MEDIUM
EPSS
0.3%
2026 CWE-79 0 PoCs

SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous elements (<script>, <iframe>, <foreignobject>) and removes on* event handlers and javascript: in href attributes. However, it does NOT block SVG animation elements (<animate>, <set>) which can dynamically set attributes to dangerous values at runtime, bypassing the static sanitization. This allows an attacker to inject executable JavaScript into the unauthenticated /api/icon/getDynamicIcon endpoint (type=8), creating a reflected XSS. This is a bypass of the fix for CVE-2026-

CVE-2026-31809
siyuan Web ⚡ nuclei
6.4
MEDIUM
EPSS
0.4%
2026 CWE-79 0 PoCs

SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attributes for the javascript: prefix using strings.HasPrefix(). However, inserting ASCII tab (&#9;), newline (&#10;), or carriage return (&#13;) characters inside the javascript: string bypasses this prefix check. Browsers strip these characters per the WHATWG URL specification before parsing the URL scheme, so the JavaScript still executes. This allows an attacker to inject executable JavaScript into the unauthenticated /api/icon/getDynamicIcon endpoint, creating a reflected XS

CVE-2026-0738
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.4
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-5774
Animated Counters Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 3 PoCs

The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-33984
SAP NetWeaver (Design Time Repository) Web
6.4
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant message. Under certain circumstances, this could lead to Cross-Site Scripting vulnerability.