13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-0337
Travelpayouts: All Travel Brands in One Place Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-0606
Focus for iOS Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

CVE-2024-7354
Ninja Forms Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13224
SlideDeck 1 Lite Content Slider Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6226
WpStickyBar Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-41333
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter.

CVE-2024-34230
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.

CVE-2024-40317
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter HTTP.

CVE-2024-2729
Otter Blocks Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.

CVE-2024-46470
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

CVE-2024-34582
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

CVE-2024-1752
Font Farsi Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-25202
Software Genérico Web
6.1
MEDIUM
EPSS
6.3%
2024 4 PoCs

Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.

CVE-2024-46336
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.

CVE-2024-42852
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2024 0 PoCs

Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.

CVE-2024-3231
Popup4Phone Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
4.8%
2024 1 PoC

The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

CVE-2019-20436
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2019 1 PoC

An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configured with an XSS payload in the dialect URI, and a user picks up this dialect's URI and adds it as the service provider claim dialect while configuring the service provider, that payload gets executed. The attacker also needs to have privileges to log in to the management console, and to add and configure claim dialects.

CVE-2019-9978
🔥 KEV Software Genérico Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
87.6%
2019 20 PoCs

The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

CVE-2019-20437
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2019 1 PoC

An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an XSS payload is configured in the identity provider basic claim configuration, that payload gets executed, if a user picks up that dialect's URI as the provisioning claim in the advanced claim configuration of the same Identity Provider. The attacker also needs to have privileges to log in to the management console, and to add and update identity provider configurations.

CVE-2019-17003
Firefox for iOS Web
6.1
MEDIUM
EPSS
0.1%
2019 1 PoC

Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.