5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6786
Payment Gateway for Telcell Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2023 1 PoC

The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2023-5354
Awesome Support Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-0013
NetWeaver AS for ABAP and ABAP Platform Web
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

CVE-2023-6555
Email Subscription Popup Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4620
Booking Calendar Web Windows
6.1
MEDIUM
EPSS
1.1%
2023 1 PoC

The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators

CVE-2023-0021
SAP NetWeaver Web
6.1
MEDIUM
EPSS
2.0%
2023 CWE-79 1 PoC

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.

CVE-2023-3083
nilsteampassnet/teampass Web
6.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-0442
Loan Comparison Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

CVE-2023-3169
tagDiv Composer Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
36.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

CVE-2023-26457
Content Server Web
6.1
MEDIUM
EPSS
0.8%
2023 CWE-79 2 PoCs

SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can read and modify some sensitive information but cannot delete the data.

CVE-2023-26140
@excalidraw/excalidraw Web
6.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.

CVE-2023-7253
Import WP Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

CVE-2023-39510
cacti Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The`reports_admin.php` script displays reporting information about graphs, devices, data sources etc. CENSUS found that an adversary that is able to configure a malicious Device name, can deploy a stored XSS attack against any user o

CVE-2023-6278
Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo DevOps Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2705
gAppointments Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin

CVE-2023-29713
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory.

CVE-2023-5238
EventPrime Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website.

CVE-2023-33732
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.

CVE-2023-2447
UserPro - Community and User Profile WordPress Plugin Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 CWE-352 1 PoC

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the 'export_users' function. This makes it possible for unauthenticated attackers to export the users to a csv file, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0968
Watu Quiz Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.0%
2023 CWE-79 0 PoCs

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.