3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-54793
astro Web Cloud ⚡ nuclei
5.5
MEDIUM
EPSS
1.0%
2025 CWE-601 2 PoCs

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs such as https://mydomain.com//malicious-site.com/. This increases the risk of phishing and other social engineering attacks. This affects sites that use on-demand rendering (SSR) with the Node or Cloudflare adapters. It does not affect static sites, or sites deployed to Netlify or Vercel. This issue i

CVE-2022-3506
barrykooij/related-posts-for-wp Web ⚡ nuclei
5.5
MEDIUM
EPSS
1.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.

CVE-2023-3521
fossbilling/fossbilling Web ⚡ nuclei
5.4
MEDIUM
EPSS
19.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.

CVE-2023-27292
OpenCATS General ⚡ nuclei
5.4
MEDIUM
EPSS
1.7%
2023 1 PoC

An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

CVE-2023-1315
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
10.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-29506
xwiki-platform General ⚡ nuclei
5.4
MEDIUM
EPSS
11.5%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

CVE-2023-40355
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
13.5%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.

CVE-2023-26842
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
13.6%
2023 1 PoC

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php.

CVE-2023-6030
LogDash Activity Log Web Database Windows ⚡ nuclei
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker

CVE-2023-6379
Open CMS Web ⚡ nuclei
5.4
MEDIUM
EPSS
18.6%
2023 CWE-79 0 PoCs

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.

CVE-2023-5914
Citrix StoreFront Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
69.8%
2023 CWE-79 0 PoCs

  Cross-site scripting (XSS)

CVE-2023-31548
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
19.2%
2023 1 PoC

A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-7246
System Dashboard Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
1.5%
2023 1 PoC

The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks

CVE-2023-28665
Woo Bulk Price Update WordPress Plugin Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
21.8%
2023 1 PoC

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

CVE-2023-1318
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-2745
WordPress Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
77.2%
2023 CWE-22 2 PoCs

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.

CVE-2023-1317
osticket/osticket Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-0552
Registration Forms Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
16.4%
2023 1 PoC

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

CVE-2023-26843
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
12.4%
2023 1 PoC

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.

CVE-2024-13099
Widget4Call Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
4.3%
2024 1 PoC

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.