38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-23808
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
52.0%
2022 3 PoCs

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVE-2024-12682
Smart Maintenance Mode Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2488
Stop Spammers Security | Block Spam Users, Comments, Forms Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-44998
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

CVE-2024-21535
markdown-to-jsx Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

CVE-2023-43770
🔥 KEV Software Genérico Web
6.1
MEDIUM
EPSS
80.4%
2023 2 PoCs

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

CVE-2024-3590
LetterPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers

CVE-2023-5758
Firefox for iOS Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.

CVE-2022-4320
WordPress Events Calendar Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
15.4%
2022 1 PoC

The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).

CVE-2024-21038
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2025-63735
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

CVE-2024-7822
Quick Code Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-4460
Uploading SVG, WEBP and ICO files Web Windows
6.1
MEDIUM
EPSS
7.3%
2023 1 PoC

The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-13331
WP Dream Carousel Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-3524
WPCode Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2024-54687
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 2 PoCs

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

CVE-2024-4924
Social Sharing Plugin Web Windows
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5811
Simple Video Directory Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2020-2751
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
0.8%
2020 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or dele

CVE-2024-55059
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.