3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-3641
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins

CVE-2024-7313
Shield Security Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
63.9%
2024 2 PoCs

The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-5809
WP Ajax Contact Form Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users

CVE-2024-25438
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.

CVE-2024-3580
Popup4Phone Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6715
Ditty Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

CVE-2024-22635
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.

CVE-2024-3637
Responsive Contact Form Builder & Lead Generation Plugin Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13822
Photo Contest | Competition | Video Contest Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-57423
Software Genérico Web Cloud
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.

CVE-2024-13853
SEO Tools Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.9%
2024 1 PoC

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13678
R3W InstaFeed Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-21017
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-10461
Firefox Web
6.1
MEDIUM
EPSS
0.9%
2024 1 PoC

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVE-2024-0238
EventON Premium Web Windows
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVE-2024-57026
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.

CVE-2024-5155
Inquiry cart Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-13225
ECT Home Page Products Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13219
Privacy Policy Genius Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-21035
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th