3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-1704
pimcore/pimcore Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE-2023-1270
btcpayserver/btcpayserver Web
5.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.

CVE-2023-53891
Blackcat CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.

CVE-2023-46297
Software Genérico Web Networking
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices. A WAN attacker can make the admin interface unreachable/invisible via an unauthenticated HTTP request. Verification of the data sent by the user does not occur. The web server does not crash, but the admin interface becomes invisible, because the files necessary to display the content are no longer available. A reboot of the router is typically required to restore the correct behavior.

CVE-2023-53978
myBB forums Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the announcement title field when adding announcements through the 'Forums and Posts' > 'Forum Announcements' interface, causing arbitrary JavaScript to execute when the announcement is displayed on the forum.

CVE-2023-53920
PodcastGenerator Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into the podcast title execute when users visit the application's home page.

CVE-2023-53916
Zenphoto Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser context.

CVE-2023-53904
Xenforo Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin panel is loaded, potentially enabling further client-side attacks.

CVE-2023-53976
myBB forums Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in the template title field when adding new templates through the 'Templates and Style' > 'Templates' > 'Manage Templates' > 'Global Templates' interface, causing arbitrary JavaScript to execute when the template is viewed.

CVE-2023-53741
Screen SFT DAB Series - Compact Radio DAB Transmitter Web
5.1
MEDIUM
EPSS
0.3%
2023 CWE-384 2 PoCs

Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reusing established sessions to remove user accounts without proper authorization.

CVE-2023-53936
Cameleon CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.

CVE-2023-54358
WordPress adivaha Travel Plugin Web Windows
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.

CVE-2023-53890
Perch Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags that execute when the file is viewed, potentially stealing user session information or performing client-side attacks.

CVE-2023-53897
Rukovoditel Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.

CVE-2023-54364
Joomla HikaShop Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.

CVE-2023-53931
revive-adserver Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payloads in prepend and append parameters to execute arbitrary JavaScript when an admin views the page.

CVE-2023-54343
QWE DL Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks, potentially leading to session hijacking and application module manipulation.

CVE-2023-1030
Online Boat Reservation System Web
5.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-53977
myBB forums Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the forum title field when adding new forums through the 'Forums and Posts' > 'Forum Management' interface, causing arbitrary JavaScript to execute when the forum listing is viewed.

CVE-2023-53915
Zenphoto Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view the album page.