3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-46081
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.

CVE-2024-0757
Insert or Embed Articulate Content into WordPress Web Windows
5.4
MEDIUM
EPSS
59.1%
2024 2 PoCs

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

CVE-2024-8444
Download Manager Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.

CVE-2024-3971
Similarity Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

CVE-2024-3939
Ditty Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-53364
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.

CVE-2024-3755
MF Gig Calendar Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10563
WooCommerce Cart Count Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-57175
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.

CVE-2024-6766
shortcodes-ultimate-pro Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-37764
Software Genérico Web
5.4
MEDIUM
EPSS
7.1%
2024 1 PoC

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

CVE-2024-51032
Software Genérico Web
5.4
MEDIUM
EPSS
1.0%
2024 2 PoCs

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.

CVE-2024-9021
Relevanssi Web Windows
5.4
MEDIUM
EPSS
0.7%
2024 1 PoC

In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor

CVE-2024-48807
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.

CVE-2024-42918
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.

CVE-2024-0881
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
13.1%
2024 1 PoC

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

CVE-2024-6134
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6536
Zephyr Project Manager Web Windows
5.4
MEDIUM
EPSS
52.0%
2024 2 PoCs

The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-39248
Software Genérico Web
5.4
MEDIUM
EPSS
1.5%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field at /admin.php.

CVE-2024-8239
Starbox Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.