5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-21149
s-cart/s-cart Web
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.

CVE-2022-4826
Simple Tooltips Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4578
Video Conferencing with Zoom Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4622
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4834
CPT Bootstrap Carousel Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21572
Communications Billing and Revenue Management Web Database
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (sco

CVE-2022-4391
Vision Interactive For WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-41206
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.

CVE-2022-4795
Galleries by Angie Makes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4464
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.

CVE-2022-4824
WP Blog and Widgets Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3987
Responsive Lightbox2 Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-0829
webmin/webmin General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-285 2 PoCs

Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

CVE-2022-4825
WP-ShowHide Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-ShowHide WordPress plugin before 1.05 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-2413
Slide Anything Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled.

CVE-2022-4491
WP-Table Reloaded Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.

CVE-2022-22402
Aspera Faspex Web
5.4
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 222571.

CVE-2022-4005
Donation Button Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2022-25875
svelte Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

CVE-2022-26950
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.