3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-5529
WP QuickLaTeX Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4381
CB (legacy) Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-11636
Email Subscribers by Icegram Express Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-23819
geoserver Web
4.8
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in the GeoServer catalog that will execute in the context of another user's browser when viewed in the MapML HTML Page. The MapML extension must be installed and access to the MapML HTML Page is available to all users although data security may limit users' ability to trigger the XSS.

CVE-2024-13357
Ditty Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8759
Nested Pages Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2696
socialdriver-framework Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-11184
wp-enable-svg Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts

CVE-2024-10149
Social Slider Feed Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11190
jwp-a11y Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2643
Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10555
WordPress Button Plugin MaxButtons Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8091
Enhanced Search Box Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-7918
Pocket Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8093
Posts reminder Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-13120
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9236
Team Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6478
CTT Expresso para WooCommerce Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10510
adBuddy+ (AdBlocker Detection) by NetfunkDesign Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7689
Snapshot Backup Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.