5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5237
Memberlite Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.5%
2023 2 PoCs

The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2023-5112
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "specials_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0366
Loan Comparison Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-43713
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

CVE-2023-4646
Simple Posts Ticker Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3521
fossbilling/fossbilling Web ⚡ nuclei
5.4
MEDIUM
EPSS
19.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.

CVE-2023-3980
omeka/omeka-s Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2.

CVE-2023-30787
MonicaHQ General
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/introductions` endpoint and first_met_additional_info parameter.

CVE-2023-3227
fossbilling/fossbilling General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-1220 1 PoC

Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-34408
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

DokuWiki before 2023-04-04a allows XSS via RSS titles.

CVE-2023-3746
ActivityPub Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

CVE-2023-26449
OX App Suite Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We are now defining the accepted media-type to avoid code execution. No publicly available exploits are known.

CVE-2023-1146
flatpressblog/flatpress Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-5167
user-activity-log-pro Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.

CVE-2023-0060
Responsive Gallery Grid Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-30097
Software Genérico Web
5.4
MEDIUM
EPSS
0.8%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field.

CVE-2023-0399
Image Over Image For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43725
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_name_long[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0542
Custom Post Type List Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0072
WC Vendors Marketplace Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.