7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4497
Jetpack CRM Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins

CVE-2022-43996
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and filenames ending in .html. When subsequently accessed via web browser, these advisories are served and interpreted as HTML pages. Such uploaded advisories can contain JavaScript code that will execute within the browser context of users inspecting the advisory.

CVE-2022-4668
Easy Appointments Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-25303
whoogle-search Web
5.4
MEDIUM
EPSS
0.3%
2022 3 PoCs

The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the [flask.render_template](https://flask.palletsprojects.com/en/2.1.x/api/flask.render_template) function. However, the error_message is rendered using the [| safe filter](https://jinja.palletsprojects.com/en/3.1.x/templates/working-with-automatic-escaping), meaning the user input is not escaped.

CVE-2022-4673
Rate my Post Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Rate my Post WordPress plugin before 3.3.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-43185
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
4.8%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVE-2022-4449
Page scroll to id Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4716
WP Popups Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Popups WordPress plugin before 2.1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3025
Bitcoin / Altcoin Faucet Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2022-39291
zoneminder Web
5.4
MEDIUM
EPSS
7.4%
2022 CWE-20 1 PoC

ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder. This was observed through an HTTP POST request containing log information to the "/zm/index.php" endpoint. Submission is not rate controlled and could affect database performance and/or consume all storage resources. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-39172
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote, authenticated, low-privileged attacker to execute arbitrary code in the victim's browser via name field of a process.

CVE-2022-3853
Supra CSV Web
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a web browser of the victim by including malicious code in a legitimate web page or web application.

CVE-2022-48085
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.

CVE-2022-4715
Structured Content (JSON-LD) #wpsc Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Structured Content WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-42141
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

CVE-2022-0596
microweber/microweber General
5.4
MEDIUM
EPSS
0.3%
2022 CWE-1284 1 PoC

Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-45613
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the publisher parameter.

CVE-2022-4478
Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-3339
Trellix ePolicy Orchestrator (ePO) Web
5.4
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO.

CVE-2022-42119
Software Genérico Web
5.4
MEDIUM
EPSS
0.6%
2022 1 PoC

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.