5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-31407
SAP Business Planning and Consolidation Web
5.4
MEDIUM
EPSS
0.4%
2023 CWE-79 2 PoCs

SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.

CVE-2023-6890
thorsten/phpmyfaq Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

CVE-2023-3575
Quiz And Survey Master Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2164
GitLab DevOps Web
5.4
MEDIUM
EPSS
52.2%
2023 CWE-79 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVE-2023-5914
Citrix StoreFront Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
69.8%
2023 CWE-79 0 PoCs

  Cross-site scripting (XSS)

CVE-2023-0267
Ultimate Carousel For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5891
pkp/pkp-lib Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVE-2023-7086
SVG Uploads Support Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-21844
PeopleSoft Enterprise PT PeopleTools Web Database
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthori

CVE-2023-5651
WP Hotel Booking Web Windows
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

CVE-2023-2516
nilsteampassnet/teampass Web
5.4
MEDIUM
EPSS
0.6%
2023 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVE-2023-1126
WP FEvents Book Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks

CVE-2023-7041
Stupid Simple CMS Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-24 1 PoC

A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newName leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248690 is the identifier assigned to this vulnerability.

CVE-2023-26450
OX App Suite Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We are now defining the accepted media-type to avoid code execution. No publicly available exploits are known.

CVE-2023-52430
Software Genérico Web
5.4
MEDIUM
EPSS
1.2%
2023 1 PoC

The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.

CVE-2023-0292
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Web Windows
5.4
MEDIUM
EPSS
0.5%
2023 CWE-352 1 PoC

The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-43702
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tracking_number" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-26445
OX App Suite Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize the theme value and use a default fallback if no theme matches. No publicly available exploits are known.

CVE-2023-43724
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0175
Responsive Clients Logo Gallery Plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.