3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-50335
SuiteCRM Web
4.9
MEDIUM
EPSS
0.8%
2024 CWE-79 1 PoC

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site Scripting (XSS), allowing an attacker to inject malicious JavaScript code. This can be exploited to steal CSRF tokens and perform unauthorized actions, such as creating new administrative users without proper authentication. The vulnerability arises due to insufficient input validation and sanitization of the Publish Key field within the SuiteCRM application. When an attacker injects a malicious s

CVE-2024-57785
Software Genérico Web
4.9
MEDIUM
EPSS
16.2%
2024 1 PoC

Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uploads.php.

CVE-2024-43442
OTRS Web
4.9
MEDIUM
EPSS
0.1%
2024 CWE-790 1 PoC

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects:  * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

CVE-2024-12680
Prisna GWT Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6130
Form Maker by 10Web Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10518
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Web Windows
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11183
Simple Side Tab Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8426
Page Builder: Pagelayer Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-8378
Safe SVG Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

CVE-2024-7716
Logo Slider Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11645
float block Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10143
MB Custom Post Types & Custom Taxonomies Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7891
Floating Contact Button Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-50859
Software Genérico Web
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

CVE-2024-0974
Social Media Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6798
DL Verification Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11921
GiveWP Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
2.0%
2024 1 PoC

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-10010
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2263
Themify Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-3635
The Post Grid Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).