13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-2366
Primavera P6 Enterprise Project Portfolio Management Web Database
6.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 17.12.0-17.12.20, 18.8.0-18.8.23, 19.12.0-19.12.14 and 20.12.0-20.12.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. While the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability c

CVE-2021-32644
ampache Web
6.4
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

CVE-2025-32809
InQuizitive Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.

CVE-2025-4126
EG-Series Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-80 1 PoC

The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes in the shortcode_title function. This makes it possible for authenticated attackers - with contributor-level access and above, on sites with the Classic Editor plugin activated - to inject arbitrary JavaScript code in the titletag attribute that will execute whenever a user access an injected page.

CVE-2025-36436
Cloud Pak for Business Automation Web Cloud
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007  is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-12045
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the category and tag 'name' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-0845
DesignThemes Core Features Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-11361
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVE-2025-52131
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

CVE-2025-32369
Xperience Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 2 PoCs

Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.

CVE-2025-4611
Slim SEO – A Fast & Automated SEO Plugin For WordPress Web Windows
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-14040
Automotive Car Dealership Business WordPress Theme Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Call to Action' custom fields in all versions up to, and including, 13.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'action_text', 'action_button_text', 'action_link', and 'action_class' custom fields. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-6258
WP SoundSystem Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-59788
Nextcloud Web Cloud
6.4
MEDIUM
EPSS
0.0%
2025 CWE-749 1 PoC

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVE-2025-57665
Software Genérico Web
6.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. This allows attackers to inject malicious URLs using dangerous protocols (javascript:, data:, file:) or redirect users to external malicious sites. While native HTML anchor elements present similar risks, UI component libraries bear additional respon

CVE-2025-12163
Omnipress Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2025-6944
Uncode Core Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and 'uncode_text_icon' shortcodes in all versions up to, and including, 2.9.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-52133
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.

CVE-2025-8015
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-52132
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.