3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-4480
WP Prayer II Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-33326
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
6.0%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter.

CVE-2024-53481
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.

CVE-2024-22717
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.

CVE-2024-11846
TravelTour Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-7354
Ninja Forms Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-37783
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 2 PoCs

A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.

CVE-2024-13328
Giga Messenger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2024 1 PoC

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12723
Infility Global Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-22551
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.

CVE-2024-12715
Asgard Security Scanner Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-25175
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.

CVE-2024-11107
System Dashboard Web Windows
6.1
MEDIUM
EPSS
1.7%
2024 1 PoC

The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

CVE-2024-6494
WordPress File Upload Web Windows
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

CVE-2024-12275
Canvasflow for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-24945
Software Genérico Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.

CVE-2024-36397
MediaAccess DGA2232 Web
6.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-31204
mailcow-dockerized DevOps Web
6.1
MEDIUM
EPSS
4.6%
2024 CWE-79 1 PoC

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability resides in the exception handling mechanism, specifically when not operating in DEV_MODE. The system saves exception details into a session array without proper sanitization or encoding. These details are later rendered into HTML and executed in a JavaScript block within the user's browser, without adequate escaping of HTML entities. This flaw allows for Cross-Site Scripting (XSS) attacks, where attackers ca

CVE-2024-2188
Archer AX50 Web
6.1
MEDIUM
EPSS
1.0%
2024 CWE-79 1 PoC

Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an execution of the JavaScript payload when the rule is loaded.

CVE-2024-1331
Team Members Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.