5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4787
Themify Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-35500
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.

CVE-2022-44950
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2022-3739
WP Best Quiz Web Windows
5.4
MEDIUM
EPSS
1.8%
2022 1 PoC

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

CVE-2022-4749
Posts List Designer by Category Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-28975
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.

CVE-2022-4657
Restaurant Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-0726
chocobozzz/peertube General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

CVE-2022-4508
ConvertKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.

CVE-2022-4472
Simple Sitemap Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-21802
grapesjs Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.

CVE-2022-4655
Welcart e-Commerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.

CVE-2022-23065
vendure Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.

CVE-2022-3002
yetiforcecompany/yetiforcecrm Web
5.4
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2022-3984
Flowplayer Video Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-44948
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.7%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".

CVE-2022-40348
Software Genérico Web
5.4
MEDIUM
EPSS
0.7%
2022 1 PoC

Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code.

CVE-2022-0731
dolibarr/dolibarr General
5.4
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-4676
OSM Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-44944
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
0.9%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.