6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-9236
Team Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7891
Floating Contact Button Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-10010
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8493
The Events Calendar Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-53620
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

CVE-2024-13493
Sensly Online Presence Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-46475
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

CVE-2024-8283
Slider by 10Web Web Windows
4.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10551
Sticky Social Icons Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10145
Hubbub Lite Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9881
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13486
Icegram Engage Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6724
Generate Images Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6783
vue Web
4.8
MEDIUM
EPSS
0.3%
2024 CWE-79 2 PoCs

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.

CVE-2024-11097
Student Record Management System General
4.8
MEDIUM
EPSS
0.0%
2024 CWE-835 1 PoC

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main Menu. The manipulation leads to infinite loop. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVE-2024-6889
Secure Copy Content Protection and Content Locking Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-21492
github.com/greenpau/caddy-security General
4.8
MEDIUM
EPSS
1.1%
2024 CWE-613 1 PoC

All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on behalf of the user.

CVE-2024-7759
PWA for WP Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12353
Phone Contact Manager System General
4.8
MEDIUM
EPSS
0.1%
2024 CWE-20 1 PoC

A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation of the argument name leads to improper input validation. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVE-2024-46226
Software Genérico Web
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.