3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-46334
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.

CVE-2024-35581
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.

CVE-2024-31847
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user input without sanitization.

CVE-2024-13628
WP Pricing Table Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.8%
2024 1 PoC

The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-8085
PeoplePond Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-36599
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.

CVE-2024-35627
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
3.7%
2024 0 PoCs

tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.

CVE-2024-4480
WP Prayer II Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-2857
Simple Buttons Creator Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.

CVE-2024-11141
Sailthru Triggermail Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13218
Fast Tube Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-25435
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter.

CVE-2024-10703
Registrations for the Events Calendar Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-33326
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.0%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter.

CVE-2024-6690
wccp-pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

CVE-2024-6494
WordPress File Upload Web Windows
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

CVE-2024-12275
Canvasflow for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-5079
wp-eMember Web Windows
6.1
MEDIUM
EPSS
2.0%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2024-6667
KBucket: Your Curated Content in WordPress Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.

CVE-2024-12723
Infility Global Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.