13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-0095
Page View Count Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-31779
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

CVE-2023-7088
Add SVG Support for Media Uploader | inventivo Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Add SVG Support for Media Uploader | inventivo WordPress plugin through 1.0.5 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-6503
WP Plugin Lister Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-0178
Annual Archive Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2414
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to modify the plugins settings, upload arbitrary files, and inject malicious JavaScript (before 4.3.2).

CVE-2023-2415
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
5.4
MEDIUM
EPSS
0.0%
2023 CWE-862 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler.

CVE-2023-0071
WP Tabs Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3372
Lana Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-26448
OX App Suite Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize jslob content for those locations to avoid redirects to malicious content. No publicly available exploits are known.

CVE-2023-50072
Software Genérico Web
5.4
MEDIUM
EPSS
3.7%
2023 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.

CVE-2023-1019
Help Desk WP Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.

CVE-2023-2964
Simple Iframe Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.

CVE-2023-49987
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.

CVE-2023-43716
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MAX_DISPLAY_NEW_PRODUCTS_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0552
Registration Forms Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
16.4%
2023 1 PoC

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

CVE-2023-5598
3DSwymer Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allow an attacker to execute arbitrary script code.

CVE-2023-5111
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "featured_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0143
Send PDF for Contact Form 7 Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-0276
Weaver Xtreme Theme Support Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.