3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-4290
Sailthru Triggermail Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13875
WP-PManager Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12708
Bulk Me Now! Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13056
Dyn Business Panel Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0672
Pz-LinkCard Web Windows
7.1
HIGH
EPSS
0.3%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13863
Stylish Google Sheet Reader 4.0 Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-0249
Advanced Schedule Posts Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2024-6529
Ultimate Classified Listings Web Windows
7.1
HIGH
EPSS
52.4%
2024 2 PoCs

The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13878
SpotBot Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-22198
nginx-ui Web
7.1
HIGH
EPSS
16.0%
2024 CWE-77 1 PoC

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow users to modify the `Terminal Start Command` setting, it is possible to do so by sending a request to the API. This issue may lead to authenticated remote code execution, privilege escalation, and information disclosure. This vulnerability has been patched in version 2.0.0.beta.9.

CVE-2024-56289
Groundhogg Web
7.1
HIGH
EPSS
7.6%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groundhogg groundhogg allows Reflected XSS.This issue affects Groundhogg: from n/a through <= 3.7.3.3.

CVE-2024-41357
Software Genérico Web
7.1
HIGH
EPSS
2.2%
2024 1 PoC

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

CVE-2024-30194
Sunshine Photo Cart Web ⚡ nuclei
7.1
HIGH
EPSS
18.7%
2024 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.

CVE-2024-5715
wp-eMember Web Windows
7.1
HIGH
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13052
Dental Optimizer Patient Generator App Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-55546
IAP-420 Web
7.1
HIGH
EPSS
0.2%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVE-2024-21285
Oracle Banking Liquidity Management Web Database
7.1
HIGH
EPSS
1.1%
2024 1 PoC

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).

CVE-2024-14015
WordPress eCommerce Plugin Web Windows ⚡ nuclei
7.1
HIGH
EPSS
0.4%
2024 1 PoC

The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13633
Simple catalogue Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-55545
IAP-420 Web
7.1
HIGH
EPSS
0.4%
2024 CWE-79 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.