2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-9978
🔥 KEV Software Genérico Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
87.6%
2019 20 PoCs

The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

CVE-2023-0942
Japanized for WooCommerce Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
39.9%
2023 CWE-79 0 PoCs

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2019-15889
Software Genérico Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
5.0%
2019 5 PoCs

The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

CVE-2023-49489
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.8%
2023 0 PoCs

Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.

CVE-2023-3936
Blog2Social: Social Media Auto Post & Scheduler Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.0%
2023 1 PoC

The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2779
Social Share, Social Login and Social Comments Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
30.8%
2023 3 PoCs

The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2021-34640
Securimage-WP-Fixed Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2021 CWE-79 0 PoCs

The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.

CVE-2021-37216
Storage Manager XN8008T Web ⚡ nuclei
6.1
MEDIUM
EPSS
11.0%
2021 CWE-79 0 PoCs

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

CVE-2021-42551
NetBiblio WebOPAC Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.7%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOPAC versions prior to 4.0.0.320; versions later than 4.0.0.328. This issue does not affect: AlCoda NetBiblio WebOPAC version 4.0.0.335 and later versions.

CVE-2021-32853
erxes Web ⚡ nuclei
6.1
MEDIUM
EPSS
84.5%
2021 CWE-79 0 PoCs

Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.

CVE-2021-40272
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
4.9%
2021 0 PoCs

OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).

CVE-2021-39322
Easy Social Icons Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
13.9%
2021 CWE-79 1 PoC

The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CVE-2021-34643
Skaut Bazar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
7.7%
2021 CWE-79 0 PoCs

The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.2.

CVE-2021-30134
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.8%
2021 1 PoC

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

CVE-2023-4148
Ditty Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
9.9%
2023 1 PoC

The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2021-39320
underConstruction Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
19.7%
2021 CWE-79 1 PoC

The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CVE-2021-39350
FV Flowplayer Video Player Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.6%
2021 CWE-79 0 PoCs

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2023-1119
WP-Optimize Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
24.2%
2023 1 PoC

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.