5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-4611
Slim SEO – A Fast & Automated SEO Plugin For WordPress Web Windows
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-59712
Snipe-IT Web
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Snipe-IT before 8.1.18 allows XSS.

CVE-2025-14040
Automotive Car Dealership Business WordPress Theme Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Call to Action' custom fields in all versions up to, and including, 13.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'action_text', 'action_button_text', 'action_link', and 'action_class' custom fields. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-4126
EG-Series Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-80 1 PoC

The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes in the shortcode_title function. This makes it possible for authenticated attackers - with contributor-level access and above, on sites with the Classic Editor plugin activated - to inject arbitrary JavaScript code in the titletag attribute that will execute whenever a user access an injected page.

CVE-2025-6258
WP SoundSystem Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-59788
Nextcloud Web Cloud
6.4
MEDIUM
EPSS
0.0%
2025 CWE-749 1 PoC

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVE-2025-57665
Software Genérico Web
6.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. This allows attackers to inject malicious URLs using dangerous protocols (javascript:, data:, file:) or redirect users to external malicious sites. While native HTML anchor elements present similar risks, UI component libraries bear additional respon

CVE-2025-56748
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

CVE-2025-54962
OpenPLC_v3 General
6.4
MEDIUM
EPSS
0.1%
2025 CWE-434 1 PoC

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI.

CVE-2025-20983
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-48731
Mattermost Confluence Plugin General
6.4
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.

CVE-2025-52131
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

CVE-2025-20943
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.

CVE-2025-52132
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.

CVE-2025-52920
InnoShop General
6.4
MEDIUM
EPSS
0.2%
2025 CWE-425 1 PoC

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their reviews of products on the website. To be specific, an attacker could view the order details of any order by browsing to /en/account/orders/_ORDER_ID_ or use the address and billing information of other customers by manipulating the shipping_address_id and billing_address_id parameters when making an order (this inform

CVE-2025-49162
VIP1113 General
6.4
MEDIUM
EPSS
0.1%
2025 CWE-424 1 PoC

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to control the local filename.

CVE-2025-11241
Yoast SEO Premium Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-80 1 PoC

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.

CVE-2025-8015
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-50071
Oracle Applications Framework Web Database
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data

CVE-2025-52133
Mocca Calendar Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.