38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-51531
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser via injecting a crafted payload into the tabfields parameter at /dpw/scripts/cgiip.exe/WService. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.

CVE-2020-2676
Hospitality OPERA 5 Property Services Web Database
6.1
MEDIUM
EPSS
0.8%
2020 1 PoC

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Printing). The supported version that is affected is 5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to s

CVE-2024-11607
GTPayment Donations Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-23078
Software Genérico Web
6.1
MEDIUM
EPSS
26.2%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

CVE-2024-24035
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 3 PoCs

Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.

CVE-2024-12587
Contact Form Master Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-1956
wpb-show-core Web Windows
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting

CVE-2023-24192
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.

CVE-2024-45878
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).

CVE-2023-0334
ShortPixel Adaptive Images Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.1%
2023 1 PoC

The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin

CVE-2023-24191
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.

CVE-2023-2399
QuBot Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 2 PoCs

The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflected on the user dashboard.

CVE-2024-51142
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

CVE-2025-20240
Cisco IOS XE Software Web Networking
6.1
MEDIUM
EPSS
0.0%
2025 CWE-692 1 PoC

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.

CVE-2024-41358
Software Genérico Web
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

CVE-2024-9651
Fluent Forms Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-46073
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.

CVE-2023-0410
builderio/qwik Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.

CVE-2024-44635
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.

CVE-2024-44771
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.