13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-2339
pimcore/pimcore Web
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-5631
🔥 KEV Roundcubemail Web
6.1
MEDIUM
EPSS
84.4%
2023 CWE-79 2 PoCs

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVE-2023-7228
illi Link Party! Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.

CVE-2023-23491
Quick Event Manager WordPress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
11.1%
2023 1 PoC

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

CVE-2023-51067
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.

CVE-2023-30111
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2023-50883
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2023 2 PoCs

ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.

CVE-2023-1915
Thumbnail carousel slider Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.

CVE-2023-0937
VK All in One Expansion Unit Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2023-25346
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
12.3%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.

CVE-2023-28106
pimcore Web
6.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch manually.

CVE-2023-1080
GN Publisher: Google News Compatible RSS Feeds Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
44.7%
2023 CWE-79 0 PoCs

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-2023
Custom 404 Pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
80.9%
2023 2 PoCs

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2023-6000
Popup Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
69.1%
2023 4 PoCs

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

CVE-2023-30106
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about.

CVE-2023-31584
Software Genérico Web
6.1
MEDIUM
EPSS
0.9%
2023 1 PoC

GitHub repository cu/silicon commit a9ef36 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the User Input field.

CVE-2023-1660
AI ChatBot Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard

CVE-2023-33988
SAP Enable Now Web
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Content-Security-Policy and X-XSS-Protection response headers are not implemented, allowing an unauthenticated attacker to attempt reflected cross-site scripting, which could result in disclosure or modification of information.

CVE-2023-33761
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php.

CVE-2023-7194
Meris Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin