7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22109
DaybydayCRM Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victim’s browser when they open the “/tasks” page to view all the tasks.

CVE-2022-41446
Software Genérico Web
5.4
MEDIUM
EPSS
3.1%
2022 2 PoCs

An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to access and modify user data.

CVE-2022-3934
FlatPM Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
4.9%
2022 1 PoC

The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2022-41242
Jenkins extreme-feedback Plugin DevOps
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.

CVE-2022-43164
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
6.0%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

CVE-2022-25854
@yaireo/tagify Web
5.4
MEDIUM
EPSS
0.8%
2022 1 PoC

This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.

CVE-2022-4785
Video Sidebar Widgets Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video Sidebar Widgets WordPress plugin through 6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-44952
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".

CVE-2022-44957
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
1.8%
2022 0 PoCs

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2022-25630
Symantec Messaging Gateway Web
5.4
MEDIUM
EPSS
1.9%
2022 1 PoC

An authenticated user can embed malicious content with XSS into the admin group policy page.

CVE-2022-4664
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Logo Slider WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4789
WPZOOM Portfolio Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4706
Genesis Columns Advanced Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Genesis Columns Advanced WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks which could be used against high-privilege users such as admins.

CVE-2022-4478
Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4467
Search & Filter Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Search & Filter WordPress plugin before 1.2.16 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-25646
x-data-spreadsheet Web
5.4
MEDIUM
EPSS
0.4%
2022 2 PoCs

All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.

CVE-2022-4469
Simple Membership Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-25979
jsuites Web
5.4
MEDIUM
EPSS
0.3%
2022 CWE-79 2 PoCs

Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function.

CVE-2022-3194
Dokan Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

CVE-2022-43166
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
4.5%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Entity".