13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-2572
Survey Maker Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-29808
Software Genérico Web
6.1
MEDIUM
EPSS
1.2%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.

CVE-2023-0733
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.6%
2023 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2023-22035
Scripting Web Database
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Scripting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some

CVE-2023-7167
Persian Fonts Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-4602
Namaste! LMS Web Windows
6.1
MEDIUM
EPSS
0.8%
2023 CWE-79 1 PoC

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-51800
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the main_settings component in the phone, address, bank, acc_name, acc_number parameters, new_class and cname parameter, add_new_parent function in the name email parameters, new_term function in the tname parameter, and the edit_student function in the name parameter.

CVE-2023-1282
Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

CVE-2023-1324
Easy Forms for Mailchimp Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1465
WP EasyPay Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin

CVE-2024-44647
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.

CVE-2024-11719
tarteaucitron-wp Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-53470
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

CVE-2024-52318
Apache Tomcat Web
6.1
MEDIUM
EPSS
15.5%
2024 1 PoC

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.

CVE-2024-27626
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.

CVE-2024-1273
Starbox Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

CVE-2024-6289
WPS Hide Login Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
7.3%
2024 1 PoC

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

CVE-2024-21042
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-35627
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
3.7%
2024 0 PoCs

tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.

CVE-2024-4534
KKProgressbar2 Free Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack