2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-55218
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

CVE-2025-51501
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.

CVE-2023-24322
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
33.8%
2023 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters.

CVE-2024-41810
twisted Web ⚡ nuclei
6.1
MEDIUM
EPSS
67.8%
2024 CWE-79 0 PoCs

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

CVE-2024-6690
wccp-pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

CVE-2024-0337
Travelpayouts: All Travel Brands in One Place Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-7354
Ninja Forms Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13224
SlideDeck 1 Lite Content Slider Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2022-42747
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2022 0 PoCs

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2024-42852
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2024 0 PoCs

Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.

CVE-2024-3231
Popup4Phone Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
4.8%
2024 1 PoC

The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

CVE-2023-6786
Payment Gateway for Telcell Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2023 1 PoC

The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2023-6697
WP Go Maps (formerly WP Google Maps) Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
54.2%
2023 CWE-79 0 PoCs

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-3169
tagDiv Composer Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
36.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

CVE-2023-0968
Watu Quiz Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.0%
2023 CWE-79 0 PoCs

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2019-9978
🔥 KEV Software Genérico Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
87.6%
2019 20 PoCs

The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

CVE-2021-34640
Securimage-WP-Fixed Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2021 CWE-79 0 PoCs

The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.

CVE-2023-0942
Japanized for WooCommerce Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
39.9%
2023 CWE-79 0 PoCs

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2021-42551
NetBiblio WebOPAC Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.7%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOPAC versions prior to 4.0.0.320; versions later than 4.0.0.328. This issue does not affect: AlCoda NetBiblio WebOPAC version 4.0.0.335 and later versions.