3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-43117
Software Genérico Web Database
5.4
MEDIUM
EPSS
2.6%
2022 2 PoCs

Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.

CVE-2022-4431
WOOCS Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4827
WP Tiles Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Tiles WordPress plugin through 1.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4306
Panda Pods Repeater Field Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.3%
2022 1 PoC

The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.

CVE-2022-4757
List Pages Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The List Pages Shortcode WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-32167
Cloudreve Web Cloud
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.

CVE-2022-4654
Pricing Tables WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4484
Social Share, Social Login and Social Comments Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-45215
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the Add New System User module.

CVE-2022-0589
librenms/librenms Web
5.4
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.

CVE-2022-4509
Content Control Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.

CVE-2022-41431
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.

CVE-2022-21377
Primavera Portfolio Management Web Database
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web API). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and 20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as we

CVE-2022-25854
@yaireo/tagify Web
5.4
MEDIUM
EPSS
0.8%
2022 1 PoC

This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.

CVE-2022-25349
materialize-css Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.

CVE-2022-4789
WPZOOM Portfolio Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-30003
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.

CVE-2022-44726
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.

CVE-2022-4625
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4362
Popup Maker Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks