3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-4819
Shared Files Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

CVE-2023-6000
Popup Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
69.1%
2023 4 PoCs

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

CVE-2023-2023
Custom 404 Pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
80.9%
2023 2 PoCs

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2023-3936
Blog2Social: Social Media Auto Post & Scheduler Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.0%
2023 1 PoC

The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-49489
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.8%
2023 0 PoCs

Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.

CVE-2023-2362
Float menu Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back

CVE-2023-3821
pimcore/pimcore Web
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-33255
Software Genérico Web
6.1
MEDIUM
EPSS
1.7%
2023 1 PoC

An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya web application.

CVE-2023-2407
Event Registration Calendar By vcita Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-45889
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 2 PoCs

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for CVE-2022-48612.

CVE-2023-30106
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about.

CVE-2023-31584
Software Genérico Web
6.1
MEDIUM
EPSS
0.9%
2023 1 PoC

GitHub repository cu/silicon commit a9ef36 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the User Input field.

CVE-2023-1660
AI ChatBot Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard

CVE-2023-22985
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments.

CVE-2023-7230
illi Link Party! Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.

CVE-2023-2337
ConvertKit Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-49539
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.

CVE-2023-2654
Conditional Menus Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-40277
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 3 PoCs

An issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in the login.jsp message parameter.

CVE-2023-27499
GUI for HTML Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the attacker will execute in the victim user's browser. The information from the victim's web browser can either be modified or read and sent to the attacker.