3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4829
Show-Hide / Collapse-Expand Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Show-Hide / Collapse-Expand WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4650
HashBar Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-22112
DaybydayCRM Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.

CVE-2022-45217
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.

CVE-2022-4392
iPanorama 360 WordPress Virtual Tour Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-24728
ckeditor4 Web
5.4
MEDIUM
EPSS
1.0%
2022 CWE-79 2 PoCs

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVE-2022-4474
Easy Social Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-35501
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.

CVE-2022-3937
Easy Video Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2022-42054
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.

CVE-2022-4672
WordPress Simple Shopping Cart Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3024
Bitcoin Satoshi Tools : Faucets, Visitor Rewarder, Satoshi Games, Referral Program Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2022-2731
openemr/openemr Web
5.4
MEDIUM
EPSS
1.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-4776
CC Child Pages Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4480
Click to Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-43144
Software Genérico Web
5.4
MEDIUM
EPSS
2.0%
2022 3 PoCs

A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-43170
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
5.4%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".

CVE-2022-4482
Carousel, Slider, Gallery by WP Carousel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4828
Bold Timeline Lite Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Bold Timeline Lite WordPress plugin before 1.1.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4394
iPages Flipbook For WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.