3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-0275
Easy Accept Payments for PayPal Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5687
mosparo/mosparo Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.

CVE-2023-43702
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tracking_number" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-43735
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "formats_titles[7]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-1146
flatpressblog/flatpress Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-0176
Giveaways and Contests by RafflePress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4821
Drag and Drop Multiple File Upload for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

CVE-2023-0168
Olevmedia Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2139
DELMIA Apriso Web
5.4
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

A reflected Cross-site Scripting (XSS) Vulnerability in DELMIA Apriso Release 2017 through Release 2022 allows an attacker to execute arbitrary script code.

CVE-2023-1318
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-0270
YaMaps for WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-52430
Software Genérico Web
5.4
MEDIUM
EPSS
1.2%
2023 1 PoC

The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.

CVE-2023-43703
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "product_info[][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-2414
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to modify the plugins settings, upload arbitrary files, and inject malicious JavaScript (before 4.3.2).

CVE-2023-43728
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_delivery_terms_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-26450
OX App Suite Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We are now defining the accepted media-type to avoid code execution. No publicly available exploits are known.

CVE-2023-30453
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter.

CVE-2023-1126
WP FEvents Book Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks

CVE-2023-33764
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component #/de/casting/show/detail/<ID>.

CVE-2023-7041
Stupid Simple CMS Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-24 1 PoC

A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newName leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248690 is the identifier assigned to this vulnerability.