3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-10076
Jetpack Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks

CVE-2024-12289
Boundary Web
5.9
MEDIUM
EPSS
0.4%
2024 CWE-460 1 PoC

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.

CVE-2024-1743
WooCommerce Customers Manager Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-8653
NetCat CMS Web
5.9
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.

CVE-2024-11357
goodlayers-core Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-27623
Software Genérico Web
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.

CVE-2024-13113
Countdown Timer for Elementor Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2024-0904
Fancy Product Designer Web Windows
5.9
MEDIUM
EPSS
0.4%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5442
Photo Gallery, Sliders, Proofing and Themes Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6224
Send email only on Reply to My Comment Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-28145
Scan2Net Web Database
5.9
MEDIUM
EPSS
0.1%
2024 CWE-89 2 PoCs

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.

CVE-2024-6390
Quiz and Survey Master (QSM) Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-50624
Software Genérico Web
5.9
MEDIUM
EPSS
0.0%
2024 2 PoCs

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.

CVE-2024-9796
WP-Advanced-Search Web Database Windows ⚡ nuclei
5.9
MEDIUM
EPSS
83.1%
2024 5 PoCs

The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2024-41738
TXSeries for Multiplatforms Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-598 1 PoC

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

CVE-2024-3753
Hostel Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
1.5%
2024 1 PoC

The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-9156
TI WooCommerce Wishlist Web Database Windows
5.9
MEDIUM
EPSS
0.6%
2024 1 PoC

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-4753
WP Secure Maintenance Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5573
Easy Table of Contents Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-2375
WPQA Builder Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks