3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-25875
svelte Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

CVE-2022-4508
ConvertKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.

CVE-2022-4478
Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4448
GiveWP Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-28975
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.

CVE-2022-4749
Posts List Designer by Category Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4657
Restaurant Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4674
Ibtana Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack

CVE-2022-3739
WP Best Quiz Web Windows
5.4
MEDIUM
EPSS
1.8%
2022 1 PoC

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

CVE-2022-22117
directus Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.

CVE-2022-25295
github.com/gophish/gophish Web
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts with multiple backslashes like \\\\\\example.com, browser will redirect user to http://example.com.

CVE-2022-4678
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-20966
Cisco Identity Services Engine Software Web Networking
5.4
MEDIUM
EPSS
2.3%
2022 CWE-79 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTM

CVE-2022-44950
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2022-35500
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.

CVE-2022-3986
WP Stripe Checkout Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-45364
Drag and Drop Multiple File Upload – Contact Form 7 Web
5.4
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.

CVE-2022-4718
Landing Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-22116
directus Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser when they open the image URL.

CVE-2022-4473
Widget Shortcode Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.