3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-25041
Cognos Analytics Web
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Assistant. IBM X-Force ID: 282780.

CVE-2024-2837
WP Chat App Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-46083
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.

CVE-2024-4940
gradio-app/gradio Web ⚡ nuclei
5.4
MEDIUM
EPSS
7.2%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that, when processed by the application, redirects the user to an attacker-controlled web page.

CVE-2024-5004
CM Popup Plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-9020
List category posts Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3058
ENL Newsletter Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-33527
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.

CVE-2024-9238
AVIF Uploader Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-4860
Software Genérico Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.

CVE-2024-34471
Software Genérico Web
5.4
MEDIUM
EPSS
1.7%
2024 1 PoC

An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.

CVE-2024-1846
Responsive Tabs Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5444
Bible Text Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5249
Akana API Platform Web
5.4
MEDIUM
EPSS
0.3%
2024 CWE-294 1 PoC

In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.

CVE-2024-11718
tarteaucitron-wp Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-55056
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

CVE-2024-4483
Email Encoder Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

CVE-2024-13826
Email Keep Web Windows
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-31649
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.

CVE-2024-33307
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.