3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-57429
Software Genérico Web
5.4
MEDIUM
EPSS
0.9%
2024 1 PoC

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

CVE-2024-5728
Animated AL List Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-26454
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.

CVE-2024-6408
Slider by 10Web Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-11841
Tithe.ly Giving Button Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-44919
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.

CVE-2024-2402
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10151
Auto iFrame Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-37799
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.

CVE-2024-11718
tarteaucitron-wp Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-24097
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

CVE-2024-12722
Twitter Bootstrap Collapse aka Accordian Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-26471
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.

CVE-2024-3026
WordPress Button Plugin MaxButtons Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-0820
Jobs for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-3965
Pray For Me Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1658
Grid Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Grid Shortcodes WordPress plugin before 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-33111
Software Genérico Web Networking
5.4
MEDIUM
EPSS
1.0%
2024 1 PoC

D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

CVE-2024-6754
Social Auto Poster Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary post metadata.

CVE-2024-51032
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.