979 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-11869
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.4%
2019 4 PoCs

The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.

CVE-2023-1780
Companion Sitemap Generator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
16.0%
2023 1 PoC

The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2019-19134
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2019 1 PoC

The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks.

CVE-2017-18491
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.

CVE-2023-5360
Royal Elementor Addons and Templates Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2023 12 PoCs

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

CVE-2019-6715
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2019 3 PoCs

pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

CVE-2019-10692
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.8%
2019 1 PoC

In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.

CVE-2017-14725
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2017 1 PoC

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVE-2019-15829
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.

CVE-2014-5187
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2014 0 PoCs

Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.

CVE-2015-1000005
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2015 0 PoCs

Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin

CVE-2023-4284
Post Timeline Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.1%
2023 1 PoC

The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2019-9881
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.9%
2019 3 PoCs

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

CVE-2019-14223
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.3%
2019 1 PoC

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).

CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2019-14789
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.

CVE-2019-9880
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 3 PoCs

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

CVE-2019-17671
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2019 2 PoCs

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVE-2015-2196
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2015 0 PoCs

SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.