13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-0236
Tutor LMS Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
20.1%
2023 1 PoC

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4603
Star CloudPRNT for WooCommerce Web Cloud Windows
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 2 PoCs

The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'printersettings' parameter in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-22055
JD Edwards EnterpriseOne Tools Web Database
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized u

CVE-2023-1377
Solidres Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-25309
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.

CVE-2023-7170
EventON-RSVP Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-24195
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.

CVE-2023-23073
Software Genérico Web
6.1
MEDIUM
EPSS
25.7%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.

CVE-2023-1596
tagDiv Composer Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-25439
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.

CVE-2023-51064
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

CVE-2023-42426
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2023 2 PoCs

Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.

CVE-2023-7151
Product Enquiry for WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-23074
Software Genérico Web
6.1
MEDIUM
EPSS
70.9%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

CVE-2023-0769
hiWeb Migration Simple Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

CVE-2023-24529
NetWeaver AS ABAP (Business Server Pages application) Web
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to hijack a user session, read and modify some sensitive information.

CVE-2023-0479
Print Invoice & Delivery Notes for WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.

CVE-2023-31285
Software Genérico Web
6.1
MEDIUM
EPSS
0.9%
2023 2 PoCs

An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user.

CVE-2023-0043
Custom Add User Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Custom Add User WordPress plugin through 2.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin