7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4482
Carousel, Slider, Gallery by WP Carousel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4765
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-41206
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.

CVE-2022-4795
Galleries by Angie Makes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4674
Ibtana Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack

CVE-2022-0437
karma-runner/karma Web ⚡ nuclei
5.4
MEDIUM
EPSS
24.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.

CVE-2022-4464
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.

CVE-2022-4394
iPages Flipbook For WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-43169
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
7.3%
2022 0 PoCs

A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Group".

CVE-2022-4714
WP Dark Mode Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack

CVE-2022-0576
librenms/librenms Web
5.4
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.

CVE-2022-4542
Compact WP Audio Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4677
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-44875
Software Genérico Web Windows
5.4
MEDIUM
EPSS
1.7%
2022 2 PoCs

KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.

CVE-2022-36923
Software Genérico Web Networking ⚡ nuclei
5.4
MEDIUM
EPSS
32.5%
2022 0 PoCs

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

CVE-2022-4478
Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4487
Easy Accordion Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4486
Meteor Slides Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-25847
serve-lite Web
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.

CVE-2022-4783
Youtube Channel Gallery Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks