38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-7688
AZIndex Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack

CVE-2025-24729
ElementInvader Addons for Elementor Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.3.3.

CVE-2023-23999
MonsterInsights Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.

CVE-2023-4145
pimcore/customer-data-framework Web
6.5
MEDIUM
EPSS
0.0%
2023 CWE-79 4 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.

CVE-2022-2470
microweber/microweber Web
6.5
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2023-3507
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack

CVE-2021-2404
PeopleSoft Enterprise HCM Candidate Gateway Web Database
6.5
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway product of Oracle PeopleSoft (component: e-mail notification). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Candidate Gateway. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Candidate Gateway accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Candidate Gateway access

CVE-2020-14744
REST Data Services Web Database
6.5
MEDIUM
EPSS
0.6%
2020 1 PoC

Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General). Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c; Standalone ORDS: prior to 20.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle REST Data Services accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC

CVE-2024-6133
wp-cart-for-digital-products Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-3853
chaskiq/chaskiq Web
6.5
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-44651
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

CVE-2025-15400
OpenPix for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.

CVE-2023-0911
WordPress Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.

CVE-2024-1287
pmpro-member-directory Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

CVE-2023-6985
10Web AI Assistant – AI content writing assistant Web Windows
6.5
MEDIUM
EPSS
7.8%
2023 CWE-862 1 PoC

The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins that can be used to gain further access to a compromised site.

CVE-2021-3728
firefly-iii/firefly-iii Web
6.5
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2024-1290
User Registration Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.

CVE-2025-50867
Software Genérico Web Database Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.

CVE-2024-6856
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2019-19982
Software Genérico Web Windows
6.5
MEDIUM
EPSS
0.4%
2019 1 PoC

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.