5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-25199
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to execute JavaScript code and obtain sensitive information in a victim's browser.

CVE-2023-46948
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.

CVE-2023-0610
wallabag/wallabag General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

CVE-2023-26982
Software Genérico Web
5.4
MEDIUM
EPSS
1.6%
2023 2 PoCs

Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.

CVE-2023-41710
OX App Suite General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVE-2023-23636
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2023 1 PoC

In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.

CVE-2023-4783
Magee Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0526
Post Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-26120
com.xuxueli:xxl-job General
5.4
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.

CVE-2023-0170
Html5 Audio Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0492
GS Products Slider for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0154
GamiPress Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0082
ExactMetrics Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-33515
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens.

CVE-2023-0034
JetWidgets For Elementor Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-47325
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.

CVE-2023-27069
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field.

CVE-2023-46344
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / no

CVE-2023-3580
squidex/squidex General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-167 1 PoC

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVE-2023-4820
PowerPress Podcasting plugin by Blubrry Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.