2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-24245
Stop Spammers Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.9%
2021 CWE-79 2 PoCs

The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

CVE-2021-24991
WooCommerce PDF Invoices & Packing Slips Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2021 CWE-79 1 PoC

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

CVE-2021-35265
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2021 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

CVE-2021-24139
Photo Gallery by 10Web Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
48.4%
2021 CWE-89 1 PoC

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

CVE-2015-5461
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.8%
2015 3 PoCs

Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

CVE-2021-24155
WordPress Backup and Migrate Plugin – Backup Guard Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2021 CWE-434 4 PoCs

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

CVE-2021-24235
Goto Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
43.8%
2021 CWE-79 1 PoC

The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.

CVE-2021-27520
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.

CVE-2021-24239
Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 1 PoC

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.

CVE-2021-35488
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.8%
2021 1 PoC

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

CVE-2021-28937
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
33.8%
2021 1 PoC

The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.

CVE-2021-26812
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
19.0%
2021 0 PoCs

Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.

CVE-2021-24891
Elementor Website Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2021 CWE-79 2 PoCs

The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

CVE-2021-27319
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.4%
2021 1 PoC

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.

CVE-2021-27310
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.

CVE-2023-50917
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2023 3 PoCs

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

CVE-2023-38192
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.

CVE-2021-24934
Visual CSS Style Editor Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2021 CWE-79 1 PoC

The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-26475
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
49.6%
2021 0 PoCs

EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.