3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4243
ImageInject Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-22345
QRadar SIEM Web
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041.

CVE-2022-4200
Login with Cognito Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-40435
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.

CVE-2022-3139
We’re Open! Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3922
Broken Link Checker Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3892
WP OAuth Server (OAuth Authentication) Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4119
Image Optimizer, Resizer and CDN Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3824
WP Admin UI Customize Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Admin UI Customize WordPress plugin before 1.5.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4142
WordPress Filter Gallery Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfiltered_html capability is disabled.

CVE-2022-3539
Testimonials Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3936
Team Members Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup).

CVE-2022-3392
WP Humans.txt Web Windows
4.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1094
amr users Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-34451
PowerPath Management Appliance Web
4.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server.

CVE-2022-4299
Metricool Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Metricool WordPress plugin before 1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3831
reCAPTCHA Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3840
Login for Google Apps Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-2574
Meks Easy Social Share Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4442
Custom Post Types and Custom Fields creator Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).