3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-10010
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2263
Themify Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-8983
Custom Twitter Feeds Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13602
Poll Maker Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8617
Quiz Maker Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-8492
Hustle Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-9835
RSS Feed Widget Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-6493
NinjaTeam Header Footer Custom Code Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-8284
Download Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-13313
AWeber Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8493
The Events Calendar Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13730
Podlove Podcast Publisher Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11319
django-cms Web
4.8
MEDIUM
EPSS
0.6%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.

CVE-2024-6094
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5286
wp-affiliate-platform Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-53620
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

CVE-2024-13482
Icegram Engage Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9428
Popup Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-56463
QRadar SIEM Web
4.8
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2024-10893
WP Booking Calendar Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).