13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2012-1872
Software Genérico Web
6.1
MEDIUM
EPSS
0.9%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."

CVE-2025-1798
design-comuni-wordpress-theme Web Windows
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.

CVE-2025-55944
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users.

CVE-2025-10357
Simple SEO Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2025-13153
Logo Slider Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-30748
PeopleSoft Enterprise PeopleTools Web Database
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result i

CVE-2025-63638
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Add Task" button.

CVE-2025-63418
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitrary JavaScript in the context of a logged-in user's session by injecting payloads via the browser's developer console. The vulnerability arises from the application's client-side code being susceptible to direct DOM manipulation without adequate sanitization or a Content Security Policy (CSP), potentially leading to account takeover and data theft.

CVE-2025-55473
Software Genérico DevOps Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. This allows an attacker to inject malicious JavaScript code that will execute in visitor browsers.

CVE-2025-44181
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via the brandname parameter.

CVE-2025-67291
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.

CVE-2025-51862
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An attacker can exploit this IDOR to tamper other users' conversation. Additionally, malicious contents and XSS payloads can be injected, leading to phishing attack, user spoofing and account hijacking via XSS.

CVE-2025-7808
WP Shopify Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-55757
Virtuemart component for Joomla Web
6.1
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

CVE-2025-0671
Icegram Express Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-6234
Hostel Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-0688
Spiritual Gifts Survey (and optional S.H.A.P.E survey) Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

CVE-2025-29688
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java.

CVE-2025-45778
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description text field.

CVE-2025-51462
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a markdown component with rehype-raw.