3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-0079
Customer Reviews for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2164
GitLab DevOps Web
5.4
MEDIUM
EPSS
52.2%
2023 CWE-79 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVE-2023-29839
Software Genérico Web
5.4
MEDIUM
EPSS
0.7%
2023 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

CVE-2023-6710
JBoss Core Services for RHEL 8 Web
5.4
MEDIUM
EPSS
1.1%
2023 CWE-79 2 PoCs

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.

CVE-2023-0374
W4 Post List Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0153
Vimeo Video Autoplay Automute Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Vimeo Video Autoplay Automute WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43723
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-7086
SVG Uploads Support Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-5942
Medialist Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0660
Smart Slider 3 Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0094
UpQode Google Maps Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0095
Page View Count Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5237
Memberlite Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.5%
2023 2 PoCs

The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2023-27070
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field.

CVE-2023-0267
Ultimate Carousel For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5891
pkp/pkp-lib Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVE-2023-5914
Citrix StoreFront Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
69.8%
2023 CWE-79 0 PoCs

  Cross-site scripting (XSS)

CVE-2023-1956
Online Computer and Laptop Store Web
5.4
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_img of the component Image Handler. The manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225343.

CVE-2023-0398
modoboa/modoboa Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-0062
EAN for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.