5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4110
Eventify™ Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3462
Highlight Focus Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3835
Kwayy HTML Sitemap Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-33727
Samsung Mobile Devices General
4.8
MEDIUM
EPSS
0.0%
2022 CWE-1021 1 PoC

A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

CVE-2022-3830
WP Page Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-42097
Software Genérico Web
4.8
MEDIUM
EPSS
0.6%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

CVE-2022-40435
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.

CVE-2022-4142
WordPress Filter Gallery Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfiltered_html capability is disabled.

CVE-2022-22125
halo Web
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.

CVE-2022-4260
WP-Ban Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
1.0%
2022 1 PoC

The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3919
Jetpack CRM Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3837
Uji Countdown Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Uji Countdown WordPress plugin before 2.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-21402
Communications Operations Monitor Web Database
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability c

CVE-2022-42096
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
21.4%
2022 2 PoCs

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

CVE-2022-42131
Software Genérico General
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.

CVE-2022-4226
Simple Basic Contact Form Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 1 PoC

The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3074
Slider Hero with Animation, Video Background Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

CVE-2022-3426
Advanced WP Columns Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Advanced WP Columns WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-36137
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.

CVE-2022-23059
Shopizer Web
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.