3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4677
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-44946
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
0.9%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

CVE-2022-3935
Welcart e-Commerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks

CVE-2022-21149
s-cart/s-cart Web
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.

CVE-2022-4826
Simple Tooltips Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-34021
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via the form fields.

CVE-2022-3096
WP Total Hacks Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

CVE-2022-4459
WP Show Posts Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The WP Show Posts WordPress plugin before 1.1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-44380
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.

CVE-2022-4578
Video Conferencing with Zoom Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4629
Product Slider for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Product Slider for WooCommerce WordPress plugin before 2.6.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-44284
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).

CVE-2022-25929
smoothie Web
5.4
MEDIUM
EPSS
0.5%
2022 3 PoCs

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

CVE-2022-39834
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2022 1 PoC

A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.

CVE-2022-4751
Word Balloon Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Word Balloon WordPress plugin before 4.19.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-42200
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.

CVE-2022-22124
halo Web
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.

CVE-2022-4622
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4756
My YouTube Channel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-0857
McAfee ePolicy Orchestrator (ePO) Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.