3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-7759
PWA for WP Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3973
House Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5578
Table of Contents Plus Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-10706
Download Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-46226
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.

CVE-2024-11189
Social Share And Social Locker Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6270
Community Events Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7052
Forminator Forms Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12739
Mobile Contact Bar Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9638
Category Posts Widget Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9227
PowerPress Podcasting plugin by Blubrry Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2024-2858
Simple Buttons Creator Web Windows
4.8
MEDIUM
EPSS
0.0%
2024 1 PoC

The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-10144
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8373
AngularJS Web
4.8
MEDIUM
EPSS
0.0%
2024 CWE-791 3 PoCs

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

CVE-2024-8701
events-calendar Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7877
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-4061
Survey Maker Web Windows
4.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2872
socialdriver-framework Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6910
EventON Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-12717
Aklamator INfeed Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).