3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-6720
Light Poll Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-4704
Contact Form 7 Web Windows
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

CVE-2024-4057
Gutenberg Blocks with AI by Kadence WP Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-13221
Fantastic ElasticSearch Web Database Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12731
Aklamator INfeed Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-1589
SendPress Newsletters Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0673
Pz-LinkCard Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-5729
Simple AL Slider Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-37783
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 2 PoCs

A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.

CVE-2024-35545
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2024-13327
Musicbox Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-11141
Sailthru Triggermail Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12736
BU Section Editing Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13218
Fast Tube Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-25435
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter.

CVE-2024-34831
Software Genérico Web
6.1
MEDIUM
EPSS
1.8%
2024 1 PoC

cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.

CVE-2024-2278
Themify Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-39090
Software Genérico Web
6.1
MEDIUM
EPSS
3.1%
2024 2 PoCs

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to account takeover.

CVE-2024-35627
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
3.7%
2024 0 PoCs

tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.

CVE-2024-36392
DeviceHub Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')