3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-47854
Software Genérico Web
6.1
MEDIUM
EPSS
4.1%
2024 2 PoCs

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.

CVE-2024-34401
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Savsoft Quiz 6.0 allows stored XSS via the index.php/quiz/insert_quiz/ quiz_name parameter.

CVE-2024-13327
Musicbox Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-44655
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.

CVE-2024-44647
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.

CVE-2024-2189
Social Icons Widget & Block by WPZOOM Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0509
WP 404 Auto Redirect to Similar Post Web Windows
6.1
MEDIUM
EPSS
33.7%
2024 CWE-79 1 PoC

The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘request’ parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-13868
URL Shortener | Conversion Tracking | AB Testing | WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6892
Journyx (jtime) Web ⚡ nuclei
6.1
MEDIUM
EPSS
7.5%
2024 CWE-81 2 PoCs

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

CVE-2024-6019
Music Request Manager Web Windows
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators

CVE-2024-2278
Themify Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-42834
Software Genérico Web
6.1
MEDIUM
EPSS
2.3%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the lastName parameter.

CVE-2024-7816
Gixaw Chat Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-6020
Sign-up Sheets Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.

CVE-2024-2445
Mattermost Web
6.1
MEDIUM
EPSS
0.4%
2024 CWE-74 1 PoC

Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.

CVE-2024-27626
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.

CVE-2024-21027
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-8032
Smooth Gallery Replacement Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-11272
Contact Form & SMTP Plugin for WordPress by PirateForms Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13619
LifterLMS Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.