3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-1780
LaTeX for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-0346
XML Sitemap Generator for Google Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2022 CWE-79 1 PoC

The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.

CVE-2022-2657
Multivendor Marketplace Solution for WooCommerce – WC Marketplace Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF

CVE-2022-1829
Inline Google Maps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-38358
Eyes of Network Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Improper neutralization of input during web page generation leaves the Eyes of Network web application vulnerable to cross-site scripting attacks at /module/admin_notifiers/rules.php and /module/report_event/indext.php via the parameters rule_notification, rule_name, and rule_name_old, and at /module/admin_user/add_modify_user.php via the parameters user_name and user_email.

CVE-2022-30982
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.

CVE-2022-34094
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2022 0 PoCs

Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via request_token.php.

CVE-2022-2273
Simple Membership Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-269 1 PoC

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.

CVE-2022-26173
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

CVE-2022-24181
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2022 2 PoCs

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

CVE-2022-0649
AdRotate – Ad manager & AdSense Ads Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-2170
Microsoft Advertising Universal Event Tracking (UET) Web Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-79 1 PoC

The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.

CVE-2022-1020
Product Table for WooCommerce (wooproducttable) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2022 CWE-862 1 PoC

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument

CVE-2022-2189
WP Video Lightbox Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2022-1764
WP-chgFontSize Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-1568
Team Members Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-0211
Shield Security – Scanners, Security Hardening, Brute Force Protection & Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2022-29733
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.

CVE-2022-2381
E Unlocked – Student Result Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack

CVE-2022-31496
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.