13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-24506
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.

CVE-2024-33669
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 2 PoCs

An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.

CVE-2024-6072
wp-cart-for-digital-products Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-13678
R3W InstaFeed Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0238
EventON Premium Web Windows
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVE-2024-5448
PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3641
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins

CVE-2024-5081
wp-eMember Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-7524
Firefox Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.

CVE-2024-8085
PeoplePond Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-52763
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.6%
2024 0 PoCs

A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "g" parameter.

CVE-2024-8032
Smooth Gallery Replacement Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-6020
Sign-up Sheets Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.

CVE-2024-2445
Mattermost Web
6.1
MEDIUM
EPSS
0.4%
2024 CWE-74 1 PoC

Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.

CVE-2024-13492
Guten Free Options Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2024 1 PoC

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6892
Journyx (jtime) Web ⚡ nuclei
6.1
MEDIUM
EPSS
7.5%
2024 CWE-81 2 PoCs

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

CVE-2024-13327
Musicbox Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-2278
Themify Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4384
CSSable Countdown Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-35545
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.