38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-2572
Survey Maker Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-0973
Widget for Social Page Feeds Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2020-6201
SAP Commerce Cloud (Testweb Extension) Web Cloud
6.1
MEDIUM
EPSS
0.4%
2020 1 PoC

The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Reflected Cross Site Scripting.

CVE-2020-27783
python-lxml Web
6.1
MEDIUM
EPSS
1.2%
2020 CWE-79 1 PoC

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

CVE-2023-29808
Software Genérico Web
6.1
MEDIUM
EPSS
1.2%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.

CVE-2024-37383
🔥 KEV Software Genérico Web
6.1
MEDIUM
EPSS
64.0%
2024 2 PoCs

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CVE-2023-0733
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.6%
2023 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2023-22035
Scripting Web Database
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Scripting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some

CVE-2023-7167
Persian Fonts Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-4652
Broadstreet Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-4602
Namaste! LMS Web Windows
6.1
MEDIUM
EPSS
0.8%
2023 CWE-79 1 PoC

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-4857
FS Product Inquiry Web Windows
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2022-43017
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

CVE-2023-51800
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the main_settings component in the phone, address, bank, acc_name, acc_number parameters, new_class and cname parameter, add_new_parent function in the name email parameters, new_term function in the tname parameter, and the edit_student function in the name parameter.

CVE-2024-13669
CalendApp Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2022-28354
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.

CVE-2022-45728
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2022-0421
Five Star Restaurant Reservations Web Windows
6.1
MEDIUM
EPSS
1.0%
2022 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments

CVE-2024-7818
Misiek Photo Album Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-1282
Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.