7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28286
Thunderbird General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVE-2022-25295
github.com/gophish/gophish Web
5.4
MEDIUM
EPSS
0.2%
2022 2 PoCs

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts with multiple backslashes like \\\\\\example.com, browser will redirect user to http://example.com.

CVE-2022-4678
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-20966
Cisco Identity Services Engine Software Web Networking
5.4
MEDIUM
EPSS
2.3%
2022 CWE-79 2 PoCs

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTM

CVE-2022-4651
Justified Gallery Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4381
Popup Maker Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-3986
WP Stripe Checkout Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-45364
Drag and Drop Multiple File Upload – Contact Form 7 Web
5.4
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.

CVE-2022-45892
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.

CVE-2022-4718
Landing Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3123
splitbrain/dokuwiki Web
5.4
MEDIUM
EPSS
0.8%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.

CVE-2022-4784
Hueman Addons Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4576
Easy Bootstrap Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-43170
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
5.4%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".

CVE-2022-25782
GateManager General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-274 1 PoC

Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7.

CVE-2022-48178
Software Genérico Web
5.4
MEDIUM
EPSS
1.9%
2022 1 PoC

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.

CVE-2022-48177
Software Genérico Web
5.4
MEDIUM
EPSS
2.5%
2022 1 PoC

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScript that will be executed by the victim user's browser.

CVE-2022-45472
Software Genérico Web
5.4
MEDIUM
EPSS
1.1%
2022 1 PoC

CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

CVE-2022-43167
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
5.9%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

CVE-2022-4653
Greenshift Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.