7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4571
Seriously Simple Podcasting Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-43165
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
4.5%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".

CVE-2022-3985
Videojs HTML5 Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4473
Widget Shortcode Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4477
Smash Balloon Social Post Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4474
Easy Social Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-46968
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2022 1 PoC

A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into sent messages.

CVE-2022-29495
Popup Builder (WordPress plugin) Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
1.5%
2022 CWE-352 0 PoCs

Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.

CVE-2022-4758
10WebMapBuilder Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The 10WebMapBuilder WordPress plugin before 1.0.72 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4551
Rich Table of Contents Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-3024
Bitcoin Satoshi Tools : Faucets, Visitor Rewarder, Satoshi Games, Referral Program Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2022-2731
openemr/openemr Web
5.4
MEDIUM
EPSS
1.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-4829
Show-Hide / Collapse-Expand Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Show-Hide / Collapse-Expand WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4392
iPanorama 360 WordPress Virtual Tour Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-40687
Creative Mail (WordPress plugin) Web Windows
5.4
MEDIUM
EPSS
1.4%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

CVE-2022-4458
amr shortcode any widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-43117
Software Genérico Web Database
5.4
MEDIUM
EPSS
2.6%
2022 2 PoCs

Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.

CVE-2022-42054
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.

CVE-2022-4828
Bold Timeline Lite Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Bold Timeline Lite WordPress plugin before 1.1.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4306
Panda Pods Repeater Field Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.3%
2022 1 PoC

The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.