5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0892
BizLibrary Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1323
Easy Forms for Mailchimp Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1525
Site Reviews Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5228
User Registration Web Windows
4.8
MEDIUM
EPSS
1.0%
2023 1 PoC

The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-6626
Product Enquiry for WooCommerce Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1654
gpac/gpac General
4.8
MEDIUM
EPSS
0.0%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.

CVE-2023-2489
Stop Spammers Security | Block Spam Users, Comments, Forms Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1554
Quick Paypal Payments Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5229
E2Pdf Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2023-6005
EventON Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-1090
SMTP Mailing Queue Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4253
AI ChatBot Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2954
liangliangyy/djangoblog Web
4.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.

CVE-2023-27711
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component.

CVE-2023-6456
WP Review Slider Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-7168
Better Follow Button for Jetpack Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5005
Autocomplete Location field Contact Form 7 Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0543
Arigato Autoresponder and Newsletter Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2023-6783
WolfNet IDX for WordPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4502
Translate WordPress with GTranslate Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters.