6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-11921
GiveWP Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
2.0%
2024 1 PoC

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-8983
Custom Twitter Feeds Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12355
Phone Contact Manager System General
4.8
MEDIUM
EPSS
0.1%
2024 CWE-20 1 PoC

A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of the file ContactBook.cpp. The manipulation leads to improper input validation. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVE-2024-3282
WP Table Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9883
Pods Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2869
Easy Property Listings Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7133
Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme Web Windows
4.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks.

CVE-2024-4621
ARForms - Premium WordPress Form Builder Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13729
Podlove Podcast Publisher Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-45960
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.

CVE-2024-11605
wp-publications Web Windows
4.8
MEDIUM
EPSS
2.0%
2024 1 PoC

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5658
CraftCMS Plugin - Two-Factor Authentication Web
4.8
MEDIUM
EPSS
0.2%
2024 CWE-303 1 PoC

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

CVE-2024-31839
Software Genérico General ⚡ nuclei
4.8
MEDIUM
EPSS
84.6%
2024 1 PoC

Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.

CVE-2024-2872
socialdriver-framework Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3261
Strong Testimonials Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed

CVE-2024-12800
IP Based Login Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7876
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-3992
Amen Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2643
Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-8091
Enhanced Search Box Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack