3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-2472
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2488
Stop Spammers Security | Block Spam Users, Comments, Forms Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0942
Japanized for WooCommerce Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
39.9%
2023 CWE-79 0 PoCs

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-23073
Software Genérico Web
6.1
MEDIUM
EPSS
25.7%
2023 1 PoC

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.

CVE-2023-4151
Store Locator WordPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
13.9%
2023 1 PoC

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2428
thorsten/phpmyfaq Web
6.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVE-2023-27008
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
39.8%
2023 1 PoC

A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.

CVE-2023-24195
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.

CVE-2023-7170
EventON-RSVP Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-39516
cacti Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_sources.php` displays the data source management information (e.g. data source path, polling configuration etc.) for different data visualizations of the _cacti_ app. CENSUS found that an adversary that i

CVE-2023-51067
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.

CVE-2023-22042
Applications Framework Web Database
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.3-12.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized upda

CVE-2023-42307
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

CVE-2023-3771
t1 Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

CVE-2023-25292
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2023 2 PoCs

Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.

CVE-2023-2571
Quiz Maker Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-30111
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2023-27499
GUI for HTML Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the attacker will execute in the victim user's browser. The information from the victim's web browser can either be modified or read and sent to the attacker.

CVE-2023-23852
Solution Manager Web
6.1
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVE-2023-3320
WP Sticky Social Web Windows
6.1
MEDIUM
EPSS
1.2%
2023 1 PoC

The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.