3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-2872
socialdriver-framework Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12717
Aklamator INfeed Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2444
Inline Related Posts Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-3937
Playlist for Youtube Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10471
Everest Forms Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-41453
Software Genérico DevOps Web
4.8
MEDIUM
EPSS
0.9%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVE-2024-26521
Software Genérico Web
4.8
MEDIUM
EPSS
1.9%
2024 1 PoC

HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component.

CVE-2024-12874
Top Comments Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12872
Zalomení Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3921
Gianism Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5026
CM Tooltip Glossary Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-50857
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.

CVE-2024-9638
Category Posts Widget Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7878
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7758
Stylish Price List Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12716
Simple Basic Contact Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12808
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10517
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Web Windows
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6927
Viral Signup Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6158
Category Posts Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)