38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-1420
Ajax Search Lite Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-46073
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.

CVE-2024-44771
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.

CVE-2024-44635
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.

CVE-2023-4250
EventPrime Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-3041
Autochat Automatic Conversation Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

CVE-2024-5730
Pagerank tools Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-51531
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser via injecting a crafted payload into the tabfields parameter at /dpw/scripts/cgiip.exe/WService. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.

CVE-2024-21025
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2023-6956
EasyAzon – Amazon Associates Affiliate Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2023 CWE-79 1 PoC

The EasyAzon – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘easyazon-cloaking-locale’ parameter in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-7082
Easy Table of Contents Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.

CVE-2023-39683
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher claims issue is present in all versions prior and later than tested version.

CVE-2023-28350
Software Genérico Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. Due to the rich and highly privileged functionality offered by the Teacher Console, the ability to silently exploit Cross Site Scripting (XSS) on the Teacher Machine enables remote code execution on any connected student machine (and the teacher's machine).

CVE-2023-1804
Product Catalog Feed by PixelYourSite Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

CVE-2024-55218
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

CVE-2022-41473
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
19.0%
2022 0 PoCs

RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.

CVE-2020-7354
Metasploit Pro Web
6.1
MEDIUM
EPSS
0.4%
2020 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target to store an XSS sequence in the Metasploit Pro console, which will trigger when the operator views the record of that scanned host in the Metasploit Pro interface. This issue affects Rapid7 Metasploit Pro version 4.17.1-20200427 and prior versions, and is fixed in Metasploit Pro version 4.17.1-20200514. See also CVE-2020-7355, which describes a similar issue, but involving the generated 'notes' field of a d

CVE-2020-2676
Hospitality OPERA 5 Property Services Web Database
6.1
MEDIUM
EPSS
0.8%
2020 1 PoC

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Printing). The supported version that is affected is 5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to s

CVE-2023-30093
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.

CVE-2025-51691
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability found in MarkTwo commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298 (May 2025) allows a remote attacker to execute arbitrary code via a crafted script input to the editor interface. The application does not properly sanitize user-supplied Markdown before rendering it. Successful exploitation could lead to session hijacking, credential theft, or arbitrary client-side code execution in the context of the victim's browser.