3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-47906
BloofoxCMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies.

CVE-2021-47913
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.

CVE-2021-47830
My SMTP Contact Plugin Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-352 2 PoCs

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

CVE-2021-47769
Isshue Shopping Cart Web Networking
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules. Attackers with privileged user accounts can inject malicious scripts that execute on preview, potentially enabling session hijacking and persistent phishing attacks.

CVE-2021-47912
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.

CVE-2021-47837
Markdownify Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload crafted markdown files with embedded scripts that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47858
Platinum-4410 Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Genexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter of the Security Management interface. Attackers can inject malicious scripts through the start source address field that will persist and trigger for privileged users when they access the security management page.

CVE-2021-47732
CMSimple Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files tabs, enabling persistent script injection.

CVE-2021-47716
orangescrum Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.

CVE-2021-47840
Moeditor Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload specially crafted markdown files with embedded JavaScript that execute when opened, potentially enabling remote code execution on the victim's system.

CVE-2021-47908
Software Genérico Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.

CVE-2021-47808
Cotonti Siena Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.

CVE-2021-47836
Markdown Explorer Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through file uploads and editor inputs. Attackers can upload markdown files with embedded JavaScript payloads to execute remote commands and potentially gain system access.

CVE-2021-47856
Easy Cart Shopping Cart Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content.

CVE-2021-47820
Ubee EVW327 Web Networking
5.1
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

CVE-2021-47722
Zucchetti Axess CLOKI Access Control Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-352 2 PoCs

Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

CVE-2021-47855
OpenLiteSpeed Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.

CVE-2021-47857
Moodle Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVE-2021-47931
Exponent CMS Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript, and the application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints.

CVE-2021-47924
Ultimate Product Catalog Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Ultimate Product Catalog 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product is viewed.