6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-13115
WP Projects Portfolio with Client Testimonials Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-5693
Firefox General
6.1
MEDIUM
EPSS
1.8%
2024 1 PoC

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVE-2024-31652
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.

CVE-2024-12275
Canvasflow for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6494
WordPress File Upload Web Windows
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

CVE-2024-6690
wccp-pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

CVE-2024-43112
Firefox for iOS Web
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

CVE-2024-0337
Travelpayouts: All Travel Brands in One Place Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-0606
Focus for iOS Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

CVE-2024-7354
Ninja Forms Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13224
SlideDeck 1 Lite Content Slider Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6226
WpStickyBar Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-41333
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter.

CVE-2024-34230
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.

CVE-2024-40317
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter HTTP.

CVE-2024-2729
Otter Blocks Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.

CVE-2024-46470
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

CVE-2024-34582
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

CVE-2024-1752
Font Farsi Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-25202
Software Genérico Web
6.1
MEDIUM
EPSS
6.3%
2024 4 PoCs

Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.