11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-3426
Advanced WP Columns Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Advanced WP Columns WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2021-31839
McAfee Agent for Windows Windows
4.8
MEDIUM
EPSS
0.0%
2021 CWE-269 1 PoC

Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify event information in the MA event folder. This allows a local user to either add false events or remove events from the event logs prior to them being sent to the ePO server.

CVE-2024-10939
Image Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9882
Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8702
Backup Database Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8619
Ajax Search Lite Web Windows
4.8
MEDIUM
EPSS
0.0%
2024 1 PoC

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3391
Retain Live Chat Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9768
Formidable Forms Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5137
Simply Excerpts Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

CVE-2022-4226
Simple Basic Contact Form Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13544
Zarinpal Paid Download Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2021-26414
Windows 10 Version 1809 Windows
4.8
MEDIUM
EPSS
9.6%
2021 1 PoC

Windows DCOM Server Security Feature Bypass

CVE-2024-6165
WANotifier Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4299
Metricool Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Metricool WordPress plugin before 1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11847
wp-svg-upload Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2021-23881
Endpoint Security (ENS) for Windows Windows
4.8
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the policy.

CVE-2024-5968
Photo Gallery by 10Web Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6693
wccp-pro Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-6163
WP Crowdfunding Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6498
Chatbot for WordPress by Collect.chat ⚡️ Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed