5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0071
WP Tabs Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3372
Lana Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-26448
OX App Suite Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize jslob content for those locations to avoid redirects to malicious content. No publicly available exploits are known.

CVE-2023-50072
Software Genérico Web
5.4
MEDIUM
EPSS
3.7%
2023 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.

CVE-2023-1019
Help Desk WP Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.

CVE-2023-23851
Business Planning and Consolidation General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-434 1 PoC

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.

CVE-2023-2964
Simple Iframe Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.

CVE-2023-49987
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.

CVE-2023-43716
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MAX_DISPLAY_NEW_PRODUCTS_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-24651
Software Genérico Database
5.4
MEDIUM
EPSS
0.3%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.

CVE-2023-0552
Registration Forms Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
16.4%
2023 1 PoC

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

CVE-2023-5598
3DSwymer Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allow an attacker to execute arbitrary script code.

CVE-2023-5111
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "featured_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-21481
Samsung Account General
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.

CVE-2023-0143
Send PDF for Contact Form 7 Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-24203
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

CVE-2023-0276
Weaver Xtreme Theme Support Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43710
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1][MODULE_SHIPPING_PERCENT_TEXT_TITLE]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0097
Post Grid, Post Carousel, & List Category Posts Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6141
Essential Real Estate Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.