38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-33255
Software Genérico Web
6.1
MEDIUM
EPSS
1.7%
2023 1 PoC

An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya web application.

CVE-2022-43017
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

CVE-2025-9163
Houzez Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2023-3821
pimcore/pimcore Web
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-5211
Fattura24 Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting vulnerability.

CVE-2023-2362
Float menu Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back

CVE-2022-0421
Five Star Restaurant Reservations Web Windows
6.1
MEDIUM
EPSS
1.0%
2022 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments

CVE-2022-21369
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update

CVE-2022-45890
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).

CVE-2023-49489
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.8%
2023 0 PoCs

Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.

CVE-2024-0673
Pz-LinkCard Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-3936
Blog2Social: Social Media Auto Post & Scheduler Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.0%
2023 1 PoC

The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13221
Fantastic ElasticSearch Web Database Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2022-4325
Post Status Notifier Lite Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.6%
2022 1 PoC

The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.

CVE-2024-12731
Aklamator INfeed Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2022-46888
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
16.2%
2022 1 PoC

Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php.

CVE-2023-45819
tinymce Web
6.1
MEDIUM
EPSS
2.2%
2023 CWE-79 1 PoC

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE's unfiltered notification system, which is used in error handling. The conditions for this exploit requires carefully crafted malicious content to have been inserted into the editor and a notification to have been triggered. When a notification was opened, the HTML within the text argument was displayed unfiltered in the notification. The vulnerability allowed arbitrary JavaScript execution when an notification presented

CVE-2024-7861
Misiek Paypal Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-39511
cacti Web
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `reports_admin.php` displays reporting information about graphs, devices, data sources etc. _CENSUS_ found that an adversary that is able to configure a malicious device name, related to a graph attached to a r

CVE-2024-4269
SVG Block Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.