3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-53568
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.

CVE-2024-45986
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.

CVE-2024-51032
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.

CVE-2024-5003
WP Stacker Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-48246
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.

CVE-2024-46082
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

CVE-2024-3636
Pinpoint Booking System Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-38430
Tafnit v8 Web
5.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-3755
MF Gig Calendar Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-30989
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.

CVE-2024-12308
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13722
NagVis Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 3 PoCs

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

CVE-2024-6536
Zephyr Project Manager Web Windows
5.4
MEDIUM
EPSS
52.0%
2024 2 PoCs

The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1306
Smart Forms Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we consider it a medium risk.

CVE-2024-10493
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-30617
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.

CVE-2024-46081
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.

CVE-2024-0757
Insert or Embed Articulate Content into WordPress Web Windows
5.4
MEDIUM
EPSS
59.1%
2024 2 PoCs

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

CVE-2024-8444
Download Manager Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.

CVE-2024-3971
Similarity Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack