3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4465
WP Video Lightbox Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-41358
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 5 PoCs

A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.

CVE-2022-3985
Videojs HTML5 Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-45472
Software Genérico Web
5.4
MEDIUM
EPSS
1.1%
2022 1 PoC

CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

CVE-2022-4664
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Logo Slider WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4706
Genesis Columns Advanced Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Genesis Columns Advanced WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks which could be used against high-privilege users such as admins.

CVE-2022-4480
Click to Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-46968
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into sent messages.

CVE-2022-25646
x-data-spreadsheet Web
5.4
MEDIUM
EPSS
0.4%
2022 2 PoCs

All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.

CVE-2022-4571
Seriously Simple Podcasting Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3194
Dokan Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

CVE-2022-45613
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the publisher parameter.

CVE-2022-44949
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.

CVE-2022-4485
Page-list Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Page-list WordPress plugin before 5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-43164
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.0%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

CVE-2022-43770
Pentaho Business Analytics Server Web
5.4
MEDIUM
EPSS
0.4%
2022 CWE-863 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.   

CVE-2022-4627
ShiftNav Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4476
Download Manager Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-44952
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".

CVE-2022-43117
Software Genérico Web Database
5.4
MEDIUM
EPSS
2.6%
2022 2 PoCs

Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.