5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4542
Compact WP Audio Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-39834
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2022 1 PoC

A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.

CVE-2022-4946
Frontend Post WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.

CVE-2022-35501
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.

CVE-2022-43170
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
5.4%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".

CVE-2022-4792
News & Blog Designer Pack Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-3339
Trellix ePolicy Orchestrator (ePO) Web
5.4
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO.

CVE-2022-4715
Structured Content (JSON-LD) #wpsc Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Structured Content WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4478
Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-45179
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials).

CVE-2022-35137
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

CVE-2022-4545
Sitemap Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-48177
Software Genérico Web
5.4
MEDIUM
EPSS
2.5%
2022 1 PoC

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScript that will be executed by the victim user's browser.

CVE-2022-4668
Easy Appointments Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4674
Ibtana Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack

CVE-2022-4666
Markup (JSON-LD) structured in schema.org Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-21450
PeopleSoft Enterprise PRTL Interaction Hub Web Database
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: My Links). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in u

CVE-2022-39172
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote, authenticated, low-privileged attacker to execute arbitrary code in the victim's browser via name field of a process.

CVE-2022-25849
joyqi/hyper-down Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.

CVE-2022-4781
Accordion Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.