13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-2837
WP Chat App Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-9020
List category posts Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3058
ENL Newsletter Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-34471
Software Genérico Web
5.4
MEDIUM
EPSS
1.7%
2024 1 PoC

An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.

CVE-2024-1846
Responsive Tabs Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-4483
Email Encoder Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

CVE-2024-37394
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.

CVE-2024-35468
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

CVE-2024-6859
WP MultiTasking Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-22855
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.

CVE-2024-29809
PhotoGallery Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

CVE-2024-54779
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVE-2024-29810
PhotoGallery Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

CVE-2024-46077
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

CVE-2024-37396
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.

CVE-2024-53408
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2024-4270
SVGMagic Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-13097
WP Finance Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6533
Directus Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover.

CVE-2024-29318
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.