1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-3862
Livemesh Addons for Elementor Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3462
Highlight Focus Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3391
Retain Live Chat Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4243
ImageInject Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3835
Kwayy HTML Sitemap Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3922
Broken Link Checker Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-2546
All-in-One WP Migration Web Windows ⚡ nuclei
4.7
MEDIUM
EPSS
16.2%
2022 5 PoCs

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

CVE-2022-34704
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
3.3%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-39050
OTRS Web Windows
4.6
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVE-2022-4562
Meks Flexible Shortcodes Web Windows
4.6
MEDIUM
EPSS
0.3%
2022 1 PoC

The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-1984
HYPR Windows WFA Windows
4.5
MEDIUM
EPSS
0.1%
2022 CWE-502 1 PoC

This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.

CVE-2022-3336
Event Monster Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack

CVE-2022-4549
Tickera Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2022-3126
Frontend File Manager Plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

CVE-2022-2450
reSmush.it : the only free Image Optimizer & compress plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.

CVE-2022-3098
Login Block IPs Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-3894
WP OAuth Server (OAuth Authentication) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.