3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-0381
Embed Swagger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
4.4%
2022 CWE-79 0 PoCs

The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0.

CVE-2022-4897
BackupBuddy Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
21.7%
2022 1 PoC

The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting

CVE-2022-4295
Show All Comments Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2022 1 PoC

The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

CVE-2022-4325
Post Status Notifier Lite Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.6%
2022 1 PoC

The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.

CVE-2022-46888
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
16.2%
2022 1 PoC

Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php.

CVE-2022-46934
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
12.9%
2022 0 PoCs

kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.

CVE-2022-43017
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

CVE-2022-3062
Simple File List Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
48.7%
2022 CWE-79 1 PoC

The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

CVE-2022-0653
Profile Builder – User Profile & User Registration Forms Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
5.7%
2022 CWE-79 0 PoCs

The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

CVE-2022-42749
CandidATS Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.7%
2022 0 PoCs

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVE-2022-41473
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
19.0%
2022 0 PoCs

RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.

CVE-2022-4971
Social Sharing Plugin – Sassy Social Share Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.1%
2022 CWE-79 1 PoC

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2022-40879
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.4%
2022 0 PoCs

kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'

CVE-2022-24682
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
88.0%
2022 0 PoCs

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CVE-2022-38467
CRM Perks Forms – WordPress Form Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
17.7%
2022 CWE-79 0 PoCs

Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.

CVE-2022-43018
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.

CVE-2022-23808
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
52.0%
2022 3 PoCs

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVE-2022-39195
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
10.0%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.

CVE-2022-2627
Newspaper Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
23.6%
2022 CWE-79 1 PoC

The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.