3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-1427
Photo Gallery by 10Web Web Windows
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.

CVE-2023-3814
Advanced File Manager Web Windows
4.9
MEDIUM
EPSS
0.2%
2023 1 PoC

The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

CVE-2023-2111
Fast & Effective Popups & Lead-Generation for WordPress Web Database Windows
4.9
MEDIUM
EPSS
0.3%
2023 1 PoC

The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.

CVE-2023-30804
Net-Gen Application Firewall Web Networking
4.9
MEDIUM
EPSS
5.2%
2023 CWE-200 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.

CVE-2023-29908
Software Genérico Web
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetMobileAPInfoById interface at /goform/aspForm.

CVE-2023-49544
Software Genérico Web
4.9
MEDIUM
EPSS
1.0%
2023 3 PoCs

A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.

CVE-2023-4109
Ninja Forms Contact Form Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.

CVE-2023-6165
Restrict Usernames Emails Characters Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-7115
Page Builder: Pagelayer Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1025
Simple File List Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-3499
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1121
Simple Giveaways Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2553
unilogies/bumsys Web
4.8
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0.

CVE-2023-0389
Calculated Fields Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-6037
WP TripAdvisor Review Slider Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-7154
Hubbub Lite (formerly Grow Social) Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1554
Quick Paypal Payments Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0893
Time Sheets Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5229
E2Pdf Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2023-1319
osticket/osticket Web
4.8
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.