7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47892
PEEL Shopping Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parameter of the purchase page. Attackers can inject malicious JavaScript payloads that will execute when the page is refreshed, potentially allowing client-side script execution.

CVE-2021-47733
CMSimple Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts by encoding payloads like ')-alert(1)// and execute arbitrary JavaScript when victims interact with delete buttons.

CVE-2021-47750
YouPHPTube Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.

CVE-2021-29253
Software Genérico General
5.1
MEDIUM
EPSS
0.1%
2021 1 PoC

The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.

CVE-2021-47842
StudyMD Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47897
PEEL Shopping Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution.

CVE-2021-47841
SnipCommand Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into command snippets. Attackers can execute arbitrary code by embedding malicious JavaScript that triggers remote command execution through file or title inputs.

CVE-2021-47844
Xmind Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.

CVE-2021-47722
Zucchetti Axess CLOKI Access Control Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-352 2 PoCs

Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

CVE-2021-47838
Markright Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads in markdown files. Attackers can upload specially crafted markdown files that execute arbitrary JavaScript when opened, potentially enabling remote code execution on the victim's system.

CVE-2021-47737
CSZ CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.

CVE-2021-47906
BloofoxCMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies.

CVE-2021-47913
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.

CVE-2021-47857
Moodle Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVE-2021-47830
My SMTP Contact Plugin Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-352 2 PoCs

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

CVE-2021-47905
MyBB Delete Account Plugin Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicious scripts that will execute in the admin interface when viewing delete account reasons.

CVE-2021-47858
Platinum-4410 Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Genexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter of the Security Management interface. Attackers can inject malicious scripts through the start source address field that will persist and trigger for privileged users when they access the security management page.

CVE-2021-47912
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.

CVE-2021-47837
Markdownify Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload crafted markdown files with embedded scripts that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47732
CMSimple Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files tabs, enabling persistent script injection.