4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-29865
Software Genérico Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.

CVE-2024-9238
AVIF Uploader Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-10146
Simple File List Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
0.9%
2024 1 PoC

The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.

CVE-2024-4756
WP Backpack Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1333
Responsive Pricing Table Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5713
If-So Dynamic Content Personalization Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-5644
Tournamatch Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10892
Cost Calculator Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-3288
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.8%
2024 1 PoC

The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3236
Popup Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-10504
Contact Form, Survey, Quiz & Popup Form Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

CVE-2024-0589
Remote Desktop Manager Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.

CVE-2024-2369
Page Builder Gutenberg Blocks Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-10818
JSFiddle Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-13101
WP MediaTagger Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5728
Animated AL List Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6408
Slider by 10Web Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-2402
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12722
Twitter Bootstrap Collapse aka Accordian Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3026
WordPress Button Plugin MaxButtons Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks