38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-60299
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread.

CVE-2022-4791
Product Slider and Carousel with Category for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-22123
halo Web
5.4
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server.

CVE-2025-67834
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.

CVE-2025-2248
WP-PManager Web Database Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2022-4580
Twenty20 Image Before-After Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Twenty20 Image Before-After WordPress plugin through 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2025-13558
Blog2Social: Social Media Auto Post & Scheduler Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the status of arbitrary posts to trash.

CVE-2024-6271
Community Events Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack

CVE-2025-51401
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.

CVE-2025-20147
Cisco Catalyst SD-WAN Manager Web Networking
5.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system.  This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacker to conduct a stored XSS attack on the affected system.

CVE-2022-21246
Communications Operations Monitor Web Database
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2022-24891
esapi-java-legacy Web
5.4
MEDIUM
EPSS
1.2%
2022 CWE-79 2 PoCs

ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause "javascript:" URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround, manually edit the **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression. More information about remediation of the vulnerability,

CVE-2020-2973
Application Express Web Database
5.4
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access

CVE-2020-11074
PrestaShop Web
5.4
MEDIUM
EPSS
0.2%
2020 CWE-79 1 PoC

In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6.

CVE-2022-3194
Dokan Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

CVE-2024-5595
Essential Blocks Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2025-3414
Structured Content (JSON-LD) #wpsc Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13722
NagVis Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-79 3 PoCs

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

CVE-2024-10493
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-25646
x-data-spreadsheet Web
5.4
MEDIUM
EPSS
0.4%
2022 2 PoCs

All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.