13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-49453
Software Genérico Web
6.1
MEDIUM
EPSS
0.6%
2023 2 PoCs

Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.

CVE-2023-1546
MyCryptoCheckout Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
29.2%
2023 1 PoC

The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-26692
Software Genérico Web
6.1
MEDIUM
EPSS
2.2%
2023 2 PoCs

ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vulnerable to Cross Site Scripting (XSS).

CVE-2023-2488
Stop Spammers Security | Block Spam Users, Comments, Forms Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-43770
🔥 KEV Software Genérico Web
6.1
MEDIUM
EPSS
80.4%
2023 2 PoCs

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

CVE-2023-5758
Firefox for iOS Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.

CVE-2023-4460
Uploading SVG, WEBP and ICO files Web Windows
6.1
MEDIUM
EPSS
7.3%
2023 1 PoC

The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-3524
WPCode Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-6621
POST SMTP Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-6161
WP Crowdfunding Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4913
cecilapp/cecil Web
6.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository cecilapp/cecil prior to 7.47.1.

CVE-2023-2303
Contact Form Builder by vcita Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.5. This is due to missing nonce validation in the vcita-callback.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-1890
Tablesome Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.3%
2023 2 PoCs

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

CVE-2023-31183
PineApp Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint.

CVE-2023-3671
MultiParcels Shipping For WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-6529
WP VR Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.

CVE-2023-1806
WP Inventory Manager Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

CVE-2023-2405
CRM and Lead Management by vcita Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This is due to missing nonce validation in the vcita-callback.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-44089
Pandora FMS Web
6.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.

CVE-2023-26776
Software Genérico Web
6.1
MEDIUM
EPSS
2.0%
2023 1 PoC

Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the title parameter of the post_receiver-services.php file.