3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-2580
AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-44767
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.

CVE-2023-28661
WP Popup Banners WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.

CVE-2023-37687
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.

CVE-2023-5737
WordPress Backup & Migration Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

CVE-2023-3131
MStore API Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

CVE-2023-44811
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the admin Password Change Function.

CVE-2023-40763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-0263
WP Yelp Review Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-41597
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2023 0 PoCs

EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

CVE-2023-27213
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.

CVE-2023-1891
Accordion & FAQ Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

CVE-2023-0431
File Away Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The File Away WordPress plugin through 3.9.9.0.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2023-27121
Software Genérico Web
N/A
UNKNOWN
EPSS
4.8%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.

CVE-2023-38875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'.

CVE-2023-4799
Magic Embeds Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-43878
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.

CVE-2023-36969
Software Genérico Web
N/A
UNKNOWN
EPSS
71.5%
2023 1 PoC

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

CVE-2023-26958
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.

CVE-2023-44824
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.