3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-7199
Relevanssi Web Windows
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request

CVE-2023-5845
Simple Social Media Share Buttons Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags

CVE-2023-5564
froxlor/froxlor Web
5.2
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.

CVE-2023-1067
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

CVE-2023-1515
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-2328
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-24515
Pandora FMS Web
5.2
MEDIUM
EPSS
0.2%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-3469
thorsten/phpmyfaq Web
5.2
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.

CVE-2023-1312
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-2322
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-3565
nilsteampassnet/teampass Web
5.2
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-2343
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-53919
PodcastGenerator Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into the Freebox content execute when users visit the application's home page.

CVE-2023-53736
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.

CVE-2023-53738
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.

CVE-2023-53906
projectSend Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.

CVE-2023-53884
Webedition CMS Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.

CVE-2023-53910
WBCE CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script content in the content parameter to execute JavaScript when users view the affected page.

CVE-2023-53925
Ulicms Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the file management interface that execute arbitrary scripts when viewed by other users.

CVE-2023-53961
Impact/Pulse/First Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-352 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page.