1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-10710
YaDisk Files Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12769
Simple Banner Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10560
Form Maker by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3920
Flattr Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13122
AFI Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6792
WP ULike Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.

CVE-2024-10545
Photo Gallery, Sliders, Proofing and Themes Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4091
Responsive Gallery Grid Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-12273
Calculated Fields Form Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11924
Icegram Express formerly known as Email Subscribers Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-0756
Insert or Embed Articulate Content into WordPress Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.

CVE-2024-12767
buddyboss-platform Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts

CVE-2024-12173
Master Slider Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12683
Smart Maintenance Mode Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13381
Calculated Fields Form Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13121
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Web Windows
3.5
LOW
EPSS
0.3%
2024 1 PoC

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13123
AFI Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13615
Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin through 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7056
WPForms Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13314
Carousel, Slider, Gallery by WP Carousel Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).