38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-1413
WP VR Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2503
10Web Social Post Feed Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-23286
Software Genérico Web
6.1
MEDIUM
EPSS
3.2%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field from the login form.

CVE-2022-0653
Profile Builder – User Profile & User Registration Forms Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
5.7%
2022 CWE-79 0 PoCs

The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

CVE-2022-21258
WebLogic Server Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle

CVE-2023-2339
pimcore/pimcore Web
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-5631
🔥 KEV Roundcubemail Web
6.1
MEDIUM
EPSS
84.4%
2023 CWE-79 2 PoCs

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVE-2023-7228
illi Link Party! Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.

CVE-2025-60374
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScript. The payload is executed in the browsers of users viewing the chat, resulting in client-side code execution, potential session token theft, and other malicious actions. A different vulnerability than CVE-2024-8867.

CVE-2019-20436
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2019 1 PoC

An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configured with an XSS payload in the dialect URI, and a user picks up this dialect's URI and adds it as the service provider claim dialect while configuring the service provider, that payload gets executed. The attacker also needs to have privileges to log in to the management console, and to add and configure claim dialects.

CVE-2020-14854
Hyperion Infrastructure Technology Web Database
6.1
MEDIUM
EPSS
0.7%
2020 1 PoC

Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Hyperion Infrastructure Technology accessible data as well as unauth

CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2025-63714
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to improper sanitization of user-supplied input when rendering generated account data to the DOM, allowing persistent injection of malicious HTML elements that execute when clicked by users.

CVE-2023-23491
Quick Event Manager WordPress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
11.1%
2023 1 PoC

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

CVE-2018-11074
Authentication Manager Web
6.1
MEDIUM
EPSS
0.7%
2018 1 PoC

RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to the browser DOM, which code is then executed by the web browser in the context of the vulnerable web application.

CVE-2025-65231
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.

CVE-2025-14312
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-3231
Popup4Phone Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
4.8%
2024 1 PoC

The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

CVE-2025-4429
Gearside Developer Dashboard Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-51067
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.