4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-9034
Wp Edit Password Protected Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2025-0368
Banner Garden Plugin for WordPress Web Windows
6.1
MEDIUM
EPSS
0.5%
2025 1 PoC

The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users.

CVE-2025-1303
Plugin Oficial Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

CVE-2025-8046
Injection Guard Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2020-11027
WordPress Web Windows
6.1
MEDIUM
EPSS
42.6%
2020 CWE-672 1 PoC

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVE-2018-6695
Threat Intelligence Exchange Server (TIE Server) Networking Windows
6.1
MEDIUM
EPSS
0.2%
2018 1 PoC

SSH host keys generation vulnerability in the server in McAfee Threat Intelligence Exchange Server (TIE Server) 1.3.0, 2.0.x, 2.1.x, 2.2.0 allows man-in-the-middle attackers to spoof servers via acquiring keys from another environment.

CVE-2018-6690
McAfee Application Control (MAC) Windows
6.1
MEDIUM
EPSS
0.0%
2018 1 PoC

Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.

CVE-2011-0096
Software Genérico Web Windows
6.1
MEDIUM
EPSS
70.1%
2011 2 PoCs

The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."

CVE-2011-1252
Software Genérico Web Windows
6.1
MEDIUM
EPSS
13.4%
2011 1 PoC

Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."

CVE-2022-4320
WordPress Events Calendar Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
15.4%
2022 1 PoC

The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).

CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-0381
Embed Swagger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
4.4%
2022 CWE-79 0 PoCs

The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0.

CVE-2022-4897
BackupBuddy Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
21.7%
2022 1 PoC

The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting

CVE-2022-3149
WP Custom Cursors Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

CVE-2022-3904
MonsterInsights Web Windows
6.1
MEDIUM
EPSS
41.3%
2022 2 PoCs

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

CVE-2022-4295
Show All Comments Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2022 1 PoC

The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

CVE-2022-4552
FL3R FeelBox Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2022-4325
Post Status Notifier Lite Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.6%
2022 1 PoC

The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.

CVE-2022-0421
Five Star Restaurant Reservations Web Windows
6.1
MEDIUM
EPSS
1.0%
2022 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments

CVE-2022-2167
Newspaper Web Windows
6.1
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting