5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1890
Tablesome Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.3%
2023 2 PoCs

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

CVE-2023-31183
PineApp Web
6.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint.

CVE-2023-3671
MultiParcels Shipping For WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1877
microweber/microweber General
6.1
MEDIUM
EPSS
4.7%
2023 CWE-77 1 PoC

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-27151
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity Number field.

CVE-2023-6529
WP VR Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.

CVE-2023-1806
WP Inventory Manager Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

CVE-2023-2405
CRM and Lead Management by vcita Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This is due to missing nonce validation in the vcita-callback.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-44089
Pandora FMS Web
6.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.

CVE-2023-26776
Software Genérico Web
6.1
MEDIUM
EPSS
2.0%
2023 1 PoC

Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the title parameter of the post_receiver-services.php file.

CVE-2023-23956
Symantec SiteMinder WebAgent Web
6.1
MEDIUM
EPSS
8.2%
2023 1 PoC

A user can supply malicious HTML and JavaScript code that will be executed in the client browser

CVE-2023-22971
Software Genérico Web Networking
6.1
MEDIUM
EPSS
1.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misuse frames, include JS/HTML code and steal sensitive information from legitimate users of the application.

CVE-2023-23853
NetWeaver Application Server for ABAP and ABAP Platform General
6.1
MEDIUM
EPSS
0.5%
2023 CWE-601 1 PoC

An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack. Vulnerability has no direct impact on availability.

CVE-2023-30148
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2023 1 PoC

Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and /sourcefiles/blockhtml.php.

CVE-2023-42307
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

CVE-2023-29623
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
27.4%
2023 1 PoC

Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.

CVE-2023-2438
UserPro - Community and User Profile WordPress Plugin Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'userpro_save_userdata' function. This makes it possible for unauthenticated attackers to update the user meta and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-2337
ConvertKit Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-5955
Contact Form Email Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-31406
SAP BusinessObjects Business Intelligence Platform General
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.