2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-60453
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management module, specifically in the app\system\column\admin\index.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.

CVE-2025-1288
WOOEXIM Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.

CVE-2025-28121
Software Genérico Web
6.1
MEDIUM
EPSS
0.7%
2025 1 PoC

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.

CVE-2025-61456
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoint. Unsanitized input in the /index parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who visits a malicious link or submits a crafted request.

CVE-2025-29686
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.

CVE-2025-43952
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.

CVE-2025-14312
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-3191
react-draft-wysiwyg Web
6.1
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.

CVE-2025-67290
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.

CVE-2025-56008
Software Genérico Web Networking
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.

CVE-2025-63640
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Save Reminder" button.

CVE-2025-61087
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.

CVE-2025-44998
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

CVE-2025-45313
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter.

CVE-2025-14313
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-51967
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.

CVE-2025-51501
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.

CVE-2025-65231
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.

CVE-2025-51862
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An attacker can exploit this IDOR to tamper other users' conversation. Additionally, malicious contents and XSS payloads can be injected, leading to phishing attack, user spoofing and account hijacking via XSS.

CVE-2025-66523
na1.foxitesign.foxit.com Web
6.1
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link. This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.