6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-29318
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.

CVE-2024-27285
yard Web
5.4
MEDIUM
EPSS
3.3%
2024 CWE-79 1 PoC

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.

CVE-2024-3633
WebP & SVG Support Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-21497
github.com/greenpau/caddy-security General
5.4
MEDIUM
EPSS
0.1%
2024 CWE-601 2 PoCs

Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection.

CVE-2024-10473
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo Slider shortcode is embed, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

CVE-2024-5417
Gutentor Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-39031
Software Genérico Web
5.4
MEDIUM
EPSS
6.7%
2024 1 PoC

In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and then add the administrator or any user to the event. When the invited user (victim) views their own profile, the payload will be executed on their side, even if they do not click on the event.

CVE-2024-4005
Social Pixel Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9879
Melapress File Monitor Web Database Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-38430
Tafnit v8 Web
5.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-3846
Chrome General
5.4
MEDIUM
EPSS
1.2%
2024 2 PoCs

Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-27665
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.

CVE-2024-42758
Software Genérico Web
5.4
MEDIUM
EPSS
1.9%
2024 1 PoC

A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A malicious attacker can input XSS payloads for example when creating or editing existing page, to trigger the XSS on Dokuwiki, which is then stored in .txt file (due to nature of how Dokuwiki is designed), which presents stored XSS.

CVE-2024-37673
Software Genérico General
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter.

CVE-2024-11841
Tithe.ly Giving Button Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-24097
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

CVE-2024-2404
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.

CVE-2024-7353
Accept Stripe Payments Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-46494
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

CVE-2024-7690
DN Popup Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack