5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-32970
xwiki-platform General ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2025 CWE-601 0 PoCs

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirects to any URL. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0.

CVE-2025-10357
Simple SEO Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2025-29719
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 2 PoCs

SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.

CVE-2025-51541
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, allowing an attacker to inject malicious JavaScript. This vulnerability can be exploited via a Cross-Site Request Forgery (CSRF) attack due to the absence of CSRF protections on the POST request. An unauthenticated remote attacker can craft a malicious web page that, when visited by a victim, stores the payload persistently in the installation

CVE-2025-45314
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function.

CVE-2025-63638
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Add Task" button.

CVE-2025-60450
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php component. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.

CVE-2025-66906
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escalated privileges.

CVE-2025-63211
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5.0-10, allows attackers to execute arbitrary code via the addName parameter to the /vbc/core/userSetupDoc/userSetupDoc endpoint.

CVE-2025-60312
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remote attacker to inject arbitrary HTML/JavaScript code that executes in the victim's browser upon clicking the "Convert to HTML" button.

CVE-2025-28121
Software Genérico Web
6.1
MEDIUM
EPSS
0.7%
2025 1 PoC

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.

CVE-2025-28073
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.

CVE-2025-14372
Chrome General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-416 1 PoC

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-29573
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.

CVE-2025-43952
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.

CVE-2025-44998
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

CVE-2025-14313
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-51501
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.

CVE-2025-56008
Software Genérico Web Networking
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.

CVE-2025-28074
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.