13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-3288
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.8%
2024 1 PoC

The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3236
Popup Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-39123
Software Genérico Web
5.4
MEDIUM
EPSS
16.4%
2024 2 PoCs

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.

CVE-2024-10504
Contact Form, Survey, Quiz & Popup Form Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

CVE-2024-0589
Remote Desktop Manager Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.

CVE-2024-46606
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

CVE-2024-2369
Page Builder Gutenberg Blocks Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-21494
github.com/greenpau/caddy-security Web
5.4
MEDIUM
EPSS
0.0%
2024 CWE-290 2 PoCs

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address.

CVE-2024-33209
Software Genérico Web
5.4
MEDIUM
EPSS
6.2%
2024 1 PoC

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.

CVE-2024-10818
JSFiddle Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13101
WP MediaTagger Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5728
Animated AL List Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-26454
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.

CVE-2024-6408
Slider by 10Web Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-2402
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-37799
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.

CVE-2024-12722
Twitter Bootstrap Collapse aka Accordian Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-26471
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.

CVE-2024-3026
WordPress Button Plugin MaxButtons Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-3965
Pray For Me Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack