2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-50071
Oracle Applications Framework Web Database
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data

CVE-2025-11241
Yoast SEO Premium Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-80 1 PoC

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.

CVE-2025-52131
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

CVE-2025-52133
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.

CVE-2025-8015
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-6944
Uncode Core Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and 'uncode_text_icon' shortcodes in all versions up to, and including, 2.9.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-59712
Snipe-IT Web
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Snipe-IT before 8.1.18 allows XSS.

CVE-2025-32809
InQuizitive Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.

CVE-2025-36436
Cloud Pak for Business Automation Web Cloud
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007  is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-32369
Xperience Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 2 PoCs

Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.

CVE-2025-0845
DesignThemes Core Features Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-11361
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVE-2025-12163
Omnipress Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2025-12045
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the category and tag 'name' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-4611
Slim SEO – A Fast & Automated SEO Plugin For WordPress Web Windows
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-15153
PbootCMS Web Database
6.3
MEDIUM
EPSS
0.1%
2025 CWE-552 1 PoC

A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. Modifying the configuration settings is advised.

CVE-2025-66502
pdfonline.foxit.com Web
6.3
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is later rendered into the DOM without proper sanitization. As a result, the injected script executes each time the affected PDF is loaded.

CVE-2025-66501
pdfonline.foxit.com Web
6.3
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored via the Identity “First Name” field, which is later rendered into the DOM without proper sanitization. As a result, the injected script may execute when predefined text is used or when viewing document properties.

CVE-2025-12628
WP 2FA Web Windows
6.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them

CVE-2025-11443
OpnForm Web
6.3
MEDIUM
EPSS
0.0%
2025 CWE-203 1 PoC

A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forgotten Password Handler. This manipulation causes information exposure through discrepancy. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The exploit has been made available to the public and could be exploited. This issue is currently aligned with Laravel issue #46465, which is why no mitigation action was taken.