3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-13605
Form Maker by 10Web Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-23642
geoserver Web
4.8
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in the GeoServer catalog that will execute in the context of another user's browser when viewed in the WMS GetMap SVG Output Format when the Simple SVG renderer is enabled. Access to the WMS SVG Format is available to all users by default although data and service security may limit u

CVE-2024-13486
Icegram Engage Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3822
Base64 Encoder/Decoder Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5658
CraftCMS Plugin - Two-Factor Authentication Web
4.8
MEDIUM
EPSS
0.2%
2024 CWE-303 1 PoC

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

CVE-2024-13127
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6724
Generate Images Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-11266
Geocache Stat Bar Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11843
Panorama Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6910
EventON Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-13616
VikBooking Hotel Booking Engine & PMS Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-45964
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

CVE-2024-7132
Page Builder Gutenberg Blocks Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6783
vue Web
4.8
MEDIUM
EPSS
0.3%
2024 CWE-79 2 PoCs

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.

CVE-2024-13382
Calculated Fields Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9182
Maspik Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-7556
Simple Share Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6393
Photo Gallery, Sliders, Proofing and Themes Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7879
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-4090
Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed