13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-0899
Steveas WP Live Chat Shoutbox Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2023-49540
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.

CVE-2023-36918
SAP Enable Now Web
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site Scripting, which could result in disclosure or modification of information.

CVE-2023-4294
URL Shortify Web Windows
6.1
MEDIUM
EPSS
32.4%
2023 2 PoCs

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

CVE-2023-48903
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.

CVE-2023-6786
Payment Gateway for Telcell Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2023 1 PoC

The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2023-5354
Awesome Support Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-0013
NetWeaver AS for ABAP and ABAP Platform Web
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

CVE-2023-6555
Email Subscription Popup Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4620
Booking Calendar Web Windows
6.1
MEDIUM
EPSS
1.1%
2023 1 PoC

The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators

CVE-2023-0021
SAP NetWeaver Web
6.1
MEDIUM
EPSS
2.0%
2023 CWE-79 1 PoC

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.

CVE-2023-3083
nilsteampassnet/teampass Web
6.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-0442
Loan Comparison Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

CVE-2023-3169
tagDiv Composer Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
36.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

CVE-2023-26457
Content Server Web
6.1
MEDIUM
EPSS
0.8%
2023 CWE-79 2 PoCs

SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can read and modify some sensitive information but cannot delete the data.

CVE-2023-26140
@excalidraw/excalidraw Web
6.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.

CVE-2023-7253
Import WP Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

CVE-2023-39510
cacti Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The`reports_admin.php` script displays reporting information about graphs, devices, data sources etc. CENSUS found that an adversary that is able to configure a malicious Device name, can deploy a stored XSS attack against any user o

CVE-2023-6278
Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo DevOps Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2705
gAppointments Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin