2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-3643
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

CVE-2025-51398
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

CVE-2025-5035
Firelight Lightbox Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with a role as low as contributors to perform stored Cross-Site Scripting attacks.

CVE-2025-15611
Popup Box Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend.

CVE-2025-11166
WP Go Maps (formerly WP Google Maps) Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic reachable via GET requests with no permission_callback. This makes it possible for unauthenticated attackers to force logged-in administrators to create, update, or delete markers and geometry features via CSRF attacks, and allows anonymous users to trigger mass deletion of markers via u

CVE-2025-2247
WP-PManager Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-50363
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.

CVE-2025-63883
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or page fragment) and inserts it into the DOM via unsafe sinks (innerHTML/insertAdjacentHTML/document.write) without proper sanitization or context-aware encoding. An attacker can craft a malicious URL that, when opened by a victim, causes arbitrary JavaScript to execute in the victim's browser under the electic-shop origin.

CVE-2025-67906
MISP Web
5.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

CVE-2025-51479
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment checks.

CVE-2025-11154
IDonate Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVE-2025-65621
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

CVE-2025-60506
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 2 PoCs

Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An attacker with a low-privileged account (e.g., Student) can inject arbitrary JavaScript payloads into a comment. When any other user (Student, Teacher, or Admin) views the annotated PDF, the payload is executed in their browser, leading to session hijacking, credential theft, or other attacker-controlled actions.

CVE-2025-51971
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary JavaScript code.

CVE-2025-0054
SAP NetWeaver Application Server Java Web
5.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the attacker might be able to read or modify information associated with the vulnerable web page.

CVE-2025-70458
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.

CVE-2025-46719
open-webui Web
5.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executed in the user's browser every time that chat transcript is opened, allowing attackers to retrieve the user's access token and gain full control over their account. Chat transcripts can be shared with other users in the same server, or with the whole open-webui community if "Enable Community Sharing"

CVE-2025-55579
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.

CVE-2025-51397
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.

CVE-2025-3414
Structured Content (JSON-LD) #wpsc Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.