13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-3548
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-3867
Tainacan Interface Web Windows
6.1
MEDIUM
EPSS
22.7%
2024 CWE-79 1 PoC

The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-2387
AFI – The Easiest Integration Plugin Web Database Windows
6.1
MEDIUM
EPSS
44.8%
2024 CWE-89 1 PoC

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries and subsequently inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing

CVE-2024-12724
WP DeskLite Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-21034
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-6018
Music Request Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-21037
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-6712
MapFig Studio Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-13630
NewsTicker Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.7%
2024 1 PoC

The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13865
S3Player Web Cloud Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

CVE-2024-7692
Flaming Forms Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-48758
Software Genérico Web
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code

CVE-2024-12726
ClipArt Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-4900
SEOPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post

CVE-2024-36395
WFO Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-80 1 PoC

Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVE-2024-33893
Software Genérico Web Cloud
6.1
MEDIUM
EPSS
1.6%
2024 2 PoCs

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.

CVE-2024-37888
ckeditor-plugin-openlink Web
6.1
MEDIUM
EPSS
20.6%
2024 CWE-79 1 PoC

The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < **1.0.5**.

CVE-2024-25551
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.

CVE-2024-27744
Software Genérico Web
6.1
MEDIUM
EPSS
4.1%
2024 1 PoC

Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.

CVE-2024-6076
wp-cart-for-digital-products Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin