3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-53985
Zstore Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context.

CVE-2023-53876
Academy LMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-434 1 PoC

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.

CVE-2023-53939
TinyWebGallery Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.

CVE-2023-54360
Joomla JLex Review Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking or credential theft.

CVE-2023-5269
Best Courier Management System Web Database
5.1
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument id/s leads to sql injection. The exploit has been disclosed to the public and may be used.

CVE-2023-54349
AmazCart CMS Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Attackers can enter script tags in the search box to execute arbitrary JavaScript that fires when search history is viewed or results are displayed.

CVE-2023-53938
RockMongo Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability by submitting crafted payloads in database, collection, and login parameters to execute arbitrary JavaScript in victim's browser.

CVE-2023-1111
FastCMS Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266126 is the identifier assigned to this vulnerability.

CVE-2023-53870
Jorani Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information.

CVE-2023-53918
PodcastGenerator Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php).

CVE-2023-53911
Textpattern CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

CVE-2023-53927
Simple CMS Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.

CVE-2023-53932
Serendipity Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.

CVE-2023-54332
Jetpack Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.

CVE-2023-54362
Cart Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute arbitrary JavaScript in victim browsers and steal session tokens or credentials.

CVE-2023-54363
Joomla Solidres Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can craft malicious URLs containing JavaScript payloads in these parameters to steal session tokens, login credentials, or manipulate site content when victims visit the crafted links.

CVE-2023-53903
WebsiteBaker Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.

CVE-2023-53887
Zomplog Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image source and onerror attributes to execute arbitrary JavaScript code in victim's browser.

CVE-2023-1704
pimcore/pimcore Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE-2023-1270
btcpayserver/btcpayserver Web
5.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.