2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-61456
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoint. Unsanitized input in the /index parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who visits a malicious link or submits a crafted request.

CVE-2025-27637
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 3 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.

CVE-2025-50107
Oracle Universal Work Queue Web Database
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized updat

CVE-2025-61427
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the userid and password parameters.

CVE-2025-63640
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Save Reminder" button.

CVE-2025-30748
PeopleSoft Enterprise PeopleTools Web Database
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result i

CVE-2025-71179
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_bundles/search/query endpoint. These vulnerabilities are distinct from the patch for CVE-2023-4119, which only fixed XSS in query and sort_by parameters to the /academy/home/courses endpoint.

CVE-2025-57462
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file.

CVE-2025-30759
Oracle Business Intelligence Enterprise Edition Web Database
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change)

CVE-2025-63725
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.

CVE-2025-60451
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\uploadify.class.php component, specifically in the website settings module. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.

CVE-2025-29691
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.

CVE-2025-0671
Icegram Express Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-3191
react-draft-wysiwyg Web
6.1
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.

CVE-2025-57520
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 3 PoCs

A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary JavaScript which executes whenever a user views the preview panel. The vulnerability affects multiple input vectors and does not require user interaction beyond viewing the affected content.

CVE-2025-56762
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.

CVE-2025-47204
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.4%
2025 0 PoCs

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).

CVE-2025-60450
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php component. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.

CVE-2025-29526
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.

CVE-2025-63418
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitrary JavaScript in the context of a logged-in user's session by injecting payloads via the browser's developer console. The vulnerability arises from the application's client-side code being susceptible to direct DOM manipulation without adequate sanitization or a Content Security Policy (CSP), potentially leading to account takeover and data theft.