4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-41049
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
13.1%
2022 3 PoCs

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-4480
Click to Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4656
WP Visitor Statistics (Real Time Traffic) Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4747
Post Category Image With Grid and Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4789
WPZOOM Portfolio Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4362
Popup Maker Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4679
Wufoo Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Wufoo Shortcode WordPress plugin before 1.52 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4484
Social Share, Social Login and Social Comments Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4460
Sidebar Widgets by CodeLights Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.

CVE-2022-4459
WP Show Posts Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The WP Show Posts WordPress plugin before 1.1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4485
Page-list Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Page-list WordPress plugin before 5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4465
WP Video Lightbox Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-3933
Essential Real Estate Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
5.5%
2022 1 PoC

The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.

CVE-2022-4509
Content Control Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.

CVE-2022-4486
Meteor Slides Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4542
Compact WP Audio Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4946
Frontend Post WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.

CVE-2022-4792
News & Blog Designer Pack Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4715
Structured Content (JSON-LD) #wpsc Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Structured Content WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4478
Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.