3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-7041
Stupid Simple CMS Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-24 1 PoC

A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newName leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248690 is the identifier assigned to this vulnerability.

CVE-2023-4823
WP Meta and Date Remover Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

CVE-2023-33829
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
2.9%
2023 6 PoCs

A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.

CVE-2023-2516
nilsteampassnet/teampass Web
5.4
MEDIUM
EPSS
0.6%
2023 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVE-2023-5651
WP Hotel Booking Web Windows
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

CVE-2023-43724
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-26450
OX App Suite Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We are now defining the accepted media-type to avoid code execution. No publicly available exploits are known.

CVE-2023-0535
Donation Block For PayPal Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0177
Social Like Box and Page by WpDevArt Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0071
WP Tabs Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0370
WPB Advanced FAQ Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-21844
PeopleSoft Enterprise PT PeopleTools Web Database
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthori

CVE-2023-7086
SVG Uploads Support Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-6082
chartjs Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-0171
jQuery T(-) Countdown Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6778
allegroai/clearml-server Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

CVE-2023-6081
chartjs Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-6499
lasTunes Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-5167
user-activity-log-pro Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.

CVE-2023-3372
Lana Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.