5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3862
Livemesh Addons for Elementor Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3392
WP Humans.txt Web Windows
4.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3906
Easy Form Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-2983
Salat Times Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3631
OAuth Client by DigitialPixies Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-4243
ImageInject Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3922
Broken Link Checker Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1094
amr users Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3831
reCAPTCHA Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3070
Generate PDF using Contact Form 7 Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-42095
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
42.1%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVE-2022-3834
Google Forms Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4981
DCMTK General
4.8
MEDIUM
EPSS
0.0%
2022 CWE-476 2 PoCs

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit is now public and may be used. Upgrading to version 3.6.8 is sufficient to resolve this issue. The patch is identified as 957fb31e5. Upgrading the affected component is advised.

CVE-2022-4199
Link Library Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-30628
Supersmart.me – Walk Through Web
4.8
MEDIUM
EPSS
0.0%
2022 3 PoCs

It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX

CVE-2022-38489
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably.

CVE-2022-3420
Official Integration for Billingo Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.

CVE-2022-3822
Donations via PayPal Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3391
Retain Live Chat Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3753
Evaluate Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).