5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43874
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.

CVE-2023-26148
ithewei/libhv General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-93 1 PoC

All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

CVE-2023-0268
Mega Addons For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6125
salesagility/suitecrm General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

CVE-2023-22039
Agile PLM Framework Web Database
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile P

CVE-2023-0424
MS-Reviews Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks

CVE-2023-0174
WP VR Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0169
Form plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
1.3%
2023 1 PoC

The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0520
RapidExpCart Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The RapidExpCart WordPress plugin through 1.0 does not sanitize and escape the url parameter in the rapidexpcart endpoint before storing it and outputting it back in the page, leading to a Stored Cross-Site Scripting vulnerability which could be used against high-privilege users such as admin, furthermore lack of csrf protection means an attacker can trick a logged in admin to perform the attack by submitting a hidden form.

CVE-2023-7089
Easy SVG Allow Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-0273
Custom Content Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2416
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.5. This makes it possible for unauthenticated to logout a vctia connected account which would cause a denial of service on the appointment scheduler, via a forged request granted they can trick a site user into performing an action such as clicking on a link.

CVE-2023-1651
AI ChatBot Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping of the settings, this could also lead to Stored XSS

CVE-2023-6889
thorsten/phpmyfaq Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

CVE-2023-27292
OpenCATS General ⚡ nuclei
5.4
MEDIUM
EPSS
1.7%
2023 1 PoC

An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

CVE-2023-0371
EmbedSocial Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0333
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-26447
OX App Suite Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize jslob content. No publicly available exploits are known.

CVE-2023-46003
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2023 2 PoCs

I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.

CVE-2023-42143
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.