38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-6690
wccp-pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

CVE-2024-6494
WordPress File Upload Web Windows
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

CVE-2025-56762
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.

CVE-2024-12275
Canvasflow for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-33988
SAP Enable Now Web
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Content-Security-Policy and X-XSS-Protection response headers are not implemented, allowing an unauthenticated attacker to attempt reflected cross-site scripting, which could result in disclosure or modification of information.

CVE-2018-11074
Authentication Manager Web
6.1
MEDIUM
EPSS
0.7%
2018 1 PoC

RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to the browser DOM, which code is then executed by the web browser in the context of the vulnerable web application.

CVE-2023-33761
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php.

CVE-2024-31652
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.

CVE-2023-7194
Meris Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-51462
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a markdown component with rehype-raw.

CVE-2023-4151
Store Locator WordPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
13.9%
2023 1 PoC

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-27008
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
39.8%
2023 1 PoC

A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.

CVE-2025-30745
Oracle MES for Process Manufacturing Web Database
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can

CVE-2024-38436
SOX 365 Web
6.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

Commugen SOX 365 – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-13115
WP Projects Portfolio with Client Testimonials Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-39516
cacti Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_sources.php` displays the data source management information (e.g. data source path, polling configuration etc.) for different data visualizations of the _cacti_ app. CENSUS found that an adversary that i

CVE-2024-24945
Software Genérico Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.

CVE-2024-13431
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2024 CWE-79 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-41810
twisted Web ⚡ nuclei
6.1
MEDIUM
EPSS
67.8%
2024 CWE-79 0 PoCs

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.