3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-7083
Email Encoder Web Windows
3.5
LOW
EPSS
0.0%
2024 1 PoC

The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13124
Photo Gallery by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5250
Akana API Platform Web
3.5
LOW
EPSS
0.5%
2024 CWE-209 1 PoC

In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

CVE-2024-13125
Everest Forms Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4004
Advanced Cron Manager Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1103
Real Estate Management System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 2 PoCs

A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input <img src=x onerror=alert(document.cookie)> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252458 is the identifier assigned to this vulnerability.

CVE-2024-0599
Jspxcms Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\core\web\back\InfoController.java of the component Document Management Page. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250837 was assigned to this vulnerability.

CVE-2024-10710
YaDisk Files Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-51337
Software Genérico Web
3.5
LOW
EPSS
0.3%
2024 1 PoC

Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User Admin/user_manage_editProcess.php.

CVE-2024-55416
Software Genérico Web ⚡ nuclei
3.5
LOW
EPSS
1.4%
2024 0 PoCs

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

CVE-2024-3529
Complete Online Student Management System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in Campcodes Complete Online Student Management System 1.0. It has been classified as problematic. This affects an unknown part of the file students_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259899.

CVE-2024-0958
Stock Management System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of the component Add Category Handler. The manipulation of the argument Category Name/Category Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252203.

CVE-2024-12769
Simple Banner Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2220
Button contact VR Web Windows
3.5
LOW
EPSS
0.3%
2024 1 PoC

The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3542
Church Management System Web
3.5
LOW
EPSS
0.4%
2024 CWE-79 1 PoC

A vulnerability classified as problematic was found in Campcodes Church Management System 1.0. This vulnerability affects unknown code of the file /admin/add_visitor.php. The manipulation of the argument mobile leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259912.

CVE-2024-1267
Restaurant POS System Web
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-253010 is the identifier assigned to this vulnerability.

CVE-2024-10560
Form Maker by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-21242
Oracle Database Server Web Database
3.5
LOW
EPSS
0.1%
2024 1 PoC

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVS

CVE-2024-3920
Flattr Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0346
Vehicle Booking System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php of the component Feedback Page. The manipulation of the argument My Testemonial leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250114 is the identifier assigned to this vulnerability.